---
cve: "CVE-2026-20746"
severity: "MEDIUM"
cvss: 6.3
epss: "28%"
vendor: "Ping Identity"
kev: false
exploited: false
published: "2026-06-12 04:17:04"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T01:39:31+02:00"
---

# CVE-2026-20746

> 6.3 MEDIUM

## Beschreibung

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/RE:M/U:Amber
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |

## Referenzen

- <https://docs.pingidentity.com/pingdirectory/11.0/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-11-0-0-1-march-2026>
- <https://www.pingidentity.com/en/resources/downloads/pingdirectory-downloads.html>
- <https://support.pingidentity.com/s/article/SECADV052-Denial-of-Service-via-copying-virtual-attributes>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-20746) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
