CVE-2026-80327: Open Redirect in PingGateway Fragment Filter
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PingGatewayto a version that resolves this vulnerability.Fixed in 2024.11.2 - Upgrade
Upgrade
PingGatewayto a version that resolves this vulnerability.Fixed in 2025.11.2 - Upgrade
Upgrade
PingGatewayto a version that resolves this vulnerability.Fixed in 2026.3.0
Event History
Frequently Asked Questions
Does exploitation require an authenticated PingGateway account?
No. The CVSS vector indicates that no privileges are required and that exploitation is network-reachable with low attack complexity, but it requires user interaction.
What versions should be used to remediate the affected release lines?
Upgrade to 2024.11.2, 2025.11.2, or 2026.3.0 or later, as appropriate for the deployed release line.
Is service availability affected according to the CVSS assessment?
No availability impact is indicated. The assessment identifies low confidentiality and integrity impact, including low impact to a subsequent system.