CVE-2025-27935

HIGH

Ping Identity One-Time Passcode Integration Kit for PingFederate 1.0-1.0.9 & >=1.1.1 - Authentication Bypass

Title source: llm
STIX 2.1

Description

The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

Scores

CVSS v4 8.6
EPSS 0.0037
EPSS Percentile 28.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
Ping Identity/One-Time Passcode Integration Kit for PingFederate 1.0 - 1.1
Ping Identity/One-Time Passcode Integration Kit for PingFederate 1.1.1
Published Dec 04, 2025
Tracked Since Feb 18, 2026