CVE-2025-26862: PingFederate unexpected browser flow initiation in redirectless mode
Published Oct 27, 2025
·Updated
Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.
Affected Software
1 affected component
PingFederate PingFederate
Event History
Oct 27, 2025
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26862?
CVE-2025-26862 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-26862?
To mitigate CVE-2025-26862, ensure that the application is configured to use default redirect behaviors and implement proper account lockout mechanisms.
3
What systems are affected by CVE-2025-26862?
CVE-2025-26862 affects the PingFederate software when configured in a non-default redirectless mode.
4
What type of attack is possible due to CVE-2025-26862?
CVE-2025-26862 may allow for brute force login attacks against authentication forms.
5
Is there a workaround for CVE-2025-26862?
A workaround for CVE-2025-26862 includes the implementation of rate limiting on authentication attempts.