SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-20746

UNKNOWN · CVSS N/A EPSS 0.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-12 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Java.

CVE
CVE-2026-20746
Severity
UNKNOWN
CVSS
N/A
EPSS
0.28%
Java

Original NVD Description

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.