Critical severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-21391
CVE-2026-21391
Description
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.