CVE-2025-27935: Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27935?
CVE-2025-27935 is classified as a high severity vulnerability due to its ability to bypass multi-factor authentication.
How do I fix CVE-2025-27935?
To fix CVE-2025-27935, update to the latest version of the PingFederate software that includes the necessary security patches.
Which versions of PingFederate are affected by CVE-2025-27935?
CVE-2025-27935 affects various versions of PingFederate that utilize the OTP Integration Kit.
What vulnerabilities arise from CVE-2025-27935?
CVE-2025-27935 can lead to unauthorized access to sensitive systems by bypassing multi-factor authentication.
Is CVE-2025-27935 being actively exploited?
As of the latest reports, there are indications that CVE-2025-27935 is being targeted in attacks.