VYPR
Critical severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026

CVE-2026-21391

CVE-2026-21391

Description

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.