PingDirectory copying of virtual attributes leads to memory exhaustion
Summary
| CVE | CVE-2026-20746 |
|---|---|
| State | PUBLISHED |
| Assigner | Ping Identity |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-12 04:17:04 UTC |
| Updated | 2026-06-12 16:06:17 UTC |
| Description | Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values. |
Risk And Classification
Primary CVSS: v4.0 6.3 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:M/U:Amber
Problem Types: CWE-401 | CWE-401 CWE-401 Missing release of memory after effective lifetime
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/S:P/A... |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
PassiveConfidentiality
NoneIntegrity
NoneAvailability
LowSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:M/U:Amber
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Ping Identity | PingDirectory | affected 9.3.0.0 9.3.0.8 custom | Not specified |
| CNA | Ping Identity | PingDirectory | unknown 10.1.0.0 10.1.0.5 custom | Not specified |
| CNA | Ping Identity | PingDirectory | affected 10.2.0.0 10.2.0.5 custom | Not specified |
| CNA | Ping Identity | PingDirectory | affected 10.3.0.0 10.3.0.3 custom | Not specified |
| CNA | Ping Identity | PingDirectory | affected 11.0.0.0 11.0.0.1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.pingidentity.com/en/resources/downloads/pingdirectory-downloads.html | [email protected] | www.pingidentity.com | |
| support.pingidentity.com/s/article/SECADV052-Denial-of-Service-via-copying-virtual-att... | [email protected] | support.pingidentity.com | |
| docs.pingidentity.com/pingdirectory/11.0/release_notes/pd_release_notes.html | [email protected] | docs.pingidentity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.