High severity7.7NVD Advisory· Published May 2, 2022· Updated Jun 17, 2026
CVE-2022-23723
CVE-2022-23723
Description
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.4.1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:pingidentity:pingone_mfa_integration_kit:1.5:*:*:*:*:*:*:*
- (no CPE)
- Range: 1.4
Patches
Vulnerability mechanics
References
2- docs.pingidentity.com/bundle/pingfederate-pingone-mfa-ik/page/wpt1599064234202.htmlnvdRelease NotesVendor Advisory
- www.pingidentity.com/en/resources/downloads/pingfederate.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.