CVE-2026-80327
Received Received - Intake

Open Redirect Vulnerability in PingGateway

Vulnerability report for CVE-2026-80327, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Ping Identity Corporation

Description

An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Ping Identity PingGateway 7.1.0
Ping Identity PingGateway 2023.2.0
Ping Identity PingGateway 2025.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an open redirect vulnerability in PingGateway's Fragment Filter feature. It allows attackers to redirect users to malicious websites by manipulating URLs. The flaw exists in specific versions of PingGateway and has been patched in later releases.

Detection Guidance

Detecting this vulnerability requires checking if your PingGateway version is affected. Run: pinggateway --version to check the installed version. Compare it against the vulnerable versions (7.1.0 to 2024.11.1, 2025.3.0 to 2025.11.1). If using a vulnerable version, inspect HTTP requests for open redirect patterns in the Fragment Filter feature.

Impact Analysis

Attackers could trick users into visiting harmful sites, potentially leading to phishing attacks, malware downloads, or credential theft. Users might unknowingly expose sensitive data if they follow redirected links.

Mitigation Strategies

Upgrade PingGateway to a fixed version: 2024.11.2, 2025.11.2, or 2026.3.0 (or later). If immediate upgrade is not possible, disable the Fragment Filter feature or restrict access to the vulnerable endpoint via network controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80327. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart