CVE-2026-20773: Ping Identity Pingfederate

High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.

Affected products

  • Ping Identity Pingfederate: from 13.0.0, up to and including 13.0.1; from 12.3.0, up to and including 12.3.5; from 12.2.0, up to and including 12.2.7; from 12.1.0, up to and including 12.1.10; from 12.0.0, up to and including 12.0.10; from 11.3.0, up to and including 11.3.14

Published 2026-09-14. Last modified 2026-09-18.