MEDIUM 4.9 NVD
CVE-2025-32736
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized action
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.
References
- https://docs.pingidentity.com/pingfederate/13.1/release_notes/pf_release_notes.html#pingfe
- https://www.pingidentity.com/en/resources/downloads/pingfederate.html
This medium severity vulnerability with a CVSS score of 4.9 was published on 2026-08-10 via NVD.
vulnfeed aggregates 7836 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.