Security Advisory

CVE-2025-32736

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 21:54:21
Last updated 2026-08-28 19:40:37
Assigner Ping Identity
CVSS score 4.9
State PUBLISHED

Description

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.