← Back to CVE List
CVE-2026-80327NVD
Vulnerability Summary
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).
CVSS v4.0 Base Metrics — Score 5.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionActive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
Affected & Patched Versions
- Ping Identity PingGateway >= 7.1.0 and <= 7.2.0
- Ping Identity PingGateway >= 2023.2.0 and <= 2024.11.1
- Ping Identity PingGateway >= 2025.3.0 and <= 2025.11.1
- Ping Identity PingGateway 7.2.0
- Ping Identity PingGateway 2024.11.1
- Ping Identity PingGateway 2025.11.1