CVE-2022-23724: Pingidentity Pingid Integration For Windows Login

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.

Affected products

  • Pingidentity Pingid Integration For Windows Login: before 2.4.2 (fixed in 2.4.2)

Published 2022-05-04. Last modified 2026-06-17.