CVE-2023-37283: Pingidentity Pingfederate

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

Affected products

  • Pingidentity Pingfederate: from 10.3.0, up to and including 10.3.12; from 11.1.0, up to and including 11.1.7; from 11.2.0, up to and including 11.2.6; version 11.3.0 only

Published 2023-10-25. Last modified 2026-06-17.