CVE-2026-20746
MEDIUMPingDirectory copying of virtual attributes leads to memory exhaustion
Title source: cnaDescription
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.
References (3)
Core 3
Core References
Scores
CVSS v4
6.3
EPSS
0.0028
EPSS Percentile
19.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:M/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (5)
Ping Identity/PingDirectory
10.1.0.0 - 10.1.0.5
Ping Identity/PingDirectory
10.2.0.0 - 10.2.0.5
Ping Identity/PingDirectory
10.3.0.0 - 10.3.0.3
Ping Identity/PingDirectory
11.0.0.0 - 11.0.0.1
Ping Identity/PingDirectory
9.3.0.0 - 9.3.0.8
Published
Jun 12, 2026
Tracked Since
Jun 12, 2026