CVE-2026-20746: Ping Identity Pingdirectory

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.

Affected products

  • Ping Identity Pingdirectory: from 9.3.0.0, up to and including 9.3.0.8; from 10.1.0.0, up to and including 10.1.0.5; from 10.2.0.0, up to and including 10.2.0.5; from 10.3.0.0, up to and including 10.3.0.3; from 11.0.0.0, before 11.0.0.1 (fixed in 11.0.0.1)

Published 2026-06-12. Last modified 2026-08-28.