CVE-2025-26862: Ping Identity Pingfederate

None severity, CVSS 0.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

Affected products

  • Ping Identity Pingfederate: from 11.3.0, before 11.3.14 (fixed in 11.3.14); from 12.0.0, before 12.0.10 (fixed in 12.0.10); from 12.1.0, before 12.1.9 (fixed in 12.1.9); from 12.2.0, before 12.2.6 (fixed in 12.2.6); from 12.3.0, before 12.3.3 (fixed in 12.3.3)

Published 2025-10-27. Last modified 2026-10-08.