CVE-2025-32736: PingFederate Administrative Console CSRF weaknesses
Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PingFederate Administrative Consoleto a version that resolves this vulnerability.Fixed in 13.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32736?
CVE-2025-32736 has a risk severity rating of 56.
How do I fix CVE-2025-32736?
To fix CVE-2025-32736, upgrade to PingFederate version 13.1 or later.
What types of attacks are associated with CVE-2025-32736?
CVE-2025-32736 is associated with Cross-Site Request Forgery (CSRF) attacks.
What versions of PingFederate are affected by CVE-2025-32736?
PingFederate versions prior to 13.1 are vulnerable to CVE-2025-32736.
Who is affected by CVE-2025-32736?
Administrators with active sessions in the PingFederate Administrative Console may be at risk due to CVE-2025-32736.