CVE-2026-20773: 
PingFederate vulnerability analysis and mitigation

Overview

CVE-2026-20773 is a role-based access control (RBAC) vulnerability in Ping Identity PingFederate's administrative expression evaluation functionality, classified as an Incorrect Authorization flaw (CWE-863). It allows authenticated users with certain administrative roles to access expression testing capabilities beyond their intended permissions. Affected versions span multiple release lines: PingFederate 11.3.0–11.3.14, 12.0.0–12.0.10, 12.1.0–12.1.10, 12.2.0–12.2.7, 12.3.0–12.3.5, and 13.0.0–13.0.1. The vulnerability was published on September 14, 2026, with a patch available via GitHub Advisory GHSA-xffc-pg4j-3qv4. It carries a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, Ping Identity Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization) — the administrative expression evaluation endpoint does not correctly enforce role-based access controls, allowing users with lower-privileged administrative roles to invoke expression testing capabilities intended only for higher-privileged roles. The attack vector is network-based, requires low privileges (an authenticated administrative account), no user interaction, and no special attack complexity or prerequisites beyond valid credentials. The vulnerability resides specifically in PingFederate's administrative expression evaluation endpoint, as referenced in Ping Identity's security advisory SECADV054 (GitHub Advisory, Ping Identity Advisory).

Impact

Successful exploitation allows authenticated administrative users to access expression testing capabilities beyond their assigned permissions, potentially enabling unauthorized administrative operations within PingFederate. The CVSS v4.0 scoring reflects high confidentiality impact on both the vulnerable system and subsequent systems, as well as high integrity and availability impact on subsequent systems — suggesting that misuse of the expression evaluation endpoint could affect connected identity infrastructure. Given PingFederate's role as a federated identity and SSO platform, unauthorized access to expression evaluation could expose sensitive identity data or allow manipulation of authentication and authorization flows (GitHub Advisory, Ping Identity Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the publication date (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.207% (11th percentile), indicating a low near-term probability of exploitation. Exploitation requires authenticated access with at least some administrative role, limiting the attacker pool to insiders or compromised admin accounts.

Exploitation steps

  1. Obtain Administrative Credentials: Acquire credentials for a PingFederate account with a lower-privileged administrative role (e.g., through phishing, credential stuffing, or insider access).
  2. Access the Administrative Console: Authenticate to the PingFederate administrative interface over the network.
  3. Navigate to the Expression Evaluation Endpoint: Access the administrative expression evaluation endpoint (referenced in SECADV054) that is intended to be restricted to higher-privileged roles.
  4. Submit Expression Payloads: Due to the incorrect authorization check, submit expression evaluation requests that the lower-privileged role should not be permitted to execute, potentially testing or executing expressions that expose sensitive configuration data or affect identity federation behavior.
  5. Leverage Results: Use the output of unauthorized expression evaluations to gather sensitive information about the PingFederate environment or to identify further attack paths within the identity infrastructure (GitHub Advisory, Ping Identity Advisory).

Indicators of compromise

  • Logs: PingFederate administrative audit logs showing lower-privileged administrative accounts accessing the expression evaluation endpoint (/pf-admin-api/ or equivalent administrative expression evaluation paths) outside of normal operational patterns.
  • Logs: Unexpected or repeated expression evaluation requests from administrative accounts that do not typically use this functionality.
  • Network: Unusual API calls to PingFederate's administrative interface from unexpected source IPs or at unusual times, particularly targeting expression evaluation endpoints.
  • Behavioral: Administrative accounts accessing capabilities inconsistent with their assigned role, flagged by role-based access control audit reviews (Ping Identity Advisory).

Mitigation and workarounds

Ping Identity has released patches addressing this vulnerability; organizations should upgrade PingFederate to versions beyond the affected ranges: above 11.3.14, 12.0.10, 12.1.10, 12.2.7, 12.3.5, and 13.0.1 respectively. As an interim measure, administrators should review and validate RBAC configurations to ensure administrative roles are properly scoped and that access to expression evaluation functionality is restricted to only those roles that require it. Audit logs should be reviewed for any recent unauthorized access to the expression evaluation endpoint by administrative users (GitHub Advisory, Ping Identity Advisory).

Additional resources


Source: This report was generated using AI

Related PingFederate vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20773HIGH8.5
  • PingFederate logoPingFederate
  • cpe:2.3:a:pingidentity:pingfederate
NoYesSep 14, 2026
CVE-2024-25573MEDIUM6.9
  • PingFederate logoPingFederate
  • cpe:2.3:a:pingidentity:pingfederate
NoYesJun 15, 2025
CVE-2025-22854MEDIUM6.9
  • PingFederate logoPingFederate
  • cpe:2.3:a:pingidentity:pingfederate
NoYesJun 15, 2025
CVE-2024-22477MEDIUM4.3
  • PingFederate logoPingFederate
  • cpe:2.3:a:pingidentity:pingfederate
NoYesJul 09, 2024
CVE-2025-21085LOW2.1
  • PingFederate logoPingFederate
  • cpe:2.3:a:pingidentity:pingfederate
NoYesJun 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management