AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-32736

MEDIUM · CVSS 4.9 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Administrative Console of PingFederate versions prior to 13.1 is susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities, enabling attackers to execute unauthorized actions by exploiting active sessions of administrators through specially-crafted links. Organizations using affected versions should prioritize remediation to mitigate potential unauthorized access and actions within their administrative interfaces. This is particularly critical for those managing sensitive identity and access management functions.

CVE
CVE-2025-32736
Severity
MEDIUM
CVSS
4.9
EPSS
0.15%

Original NVD Description

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.