CVE-2025-26862

Publication date

2025-10-27 14:39:41

Family

Ping Identity

State

PUBLISHED

Description

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.