PatchSiren

Ping Identity CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ping Identity CVE published 2026-06-12

CVE-2026-20746

CVE-2026-20746 is a MEDIUM severity vulnerability in Ping Identity PingDirectory. The vulnerability allows authorized users to exhaust the Java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values. The vulnerability was published on 2026-06-12T04:17:04.510Z and last modified on 2026-06-12T16:06:17.027Z.

MEDIUM Ping Identity CVE published 2026-04-07

CVE-2025-20628

CVE-2025-20628 describes an insufficient granularity of access control vulnerability in PingIDM (formerly ForgeRock Identity Management). Administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode, allowing attackers to potentially spoof a client-mode RCS and intercept or modify security-relevant properties. This issue is exploitable only when an RCS is [truncated]