CVE-2025-20628

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 23:16

Updated : 2026-04-08 21:26


NVD link : CVE-2025-20628

Mitre link : CVE-2025-20628

CVE.ORG link : CVE-2025-20628


JSON object : View

Products Affected

No product.

CWE
CWE-1220

Insufficient Granularity of Access Control