CVE-2023-37283: Pingidentity Pingfederate
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Affected products
- Pingidentity Pingfederate: from 10.3.0, up to and including 10.3.12; from 11.1.0, up to and including 11.1.7; from 11.2.0, up to and including 11.2.6; version 11.3.0 only
Published 2023-10-25. Last modified 2026-06-17.