Ping Identity · Pingfederate · CVE-2025-32736
**Name of the Vulnerable Software and Affected Versions**
PingFederate versions prior to 13.1
**Description**
Cross-Site Request Forgery (CSRF) weaknesses in the Administrative Console may allow actors to perform unauthorized actions. This occurs when administrators with active sessions are triggered to click specially-crafted links. CSRF is a flaw that allows an attacker to induce a user to perform actions they did not intend to do on a different website.
**Recommendations**
Update to version 13.1 or later.