Back to Database
Status published
High
CVE-2025-27935
Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit
Vulnerability Description
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27935
Credits & Attribution
No credits recorded in the NVD database.
References
More from Ping Identity
View All →CVE-2025-26862
PingFederate unexpected browser flow initiation in redirectless mode
Unknown
0
CVE-2025-22854
Possible thread exhaustion from processing http responses in PingFederate Google Adapter
Medium
6.9
CVE-2025-21085
PingFederate OAuth Grant attribute duplication may use excessive memory
Low
2.1
CVE-2025-20628
Insufficient granularity of access control for Remote Connector Servers in client mode
Medium
6.9
CVE-2025-20059
PingAM Java Policy Agent path traversal
Critical
9.2
Affected Vendor
Ping Identity
View all reports →Affected Software
One-Time Passcode Integration Kit for PingFederate
Vulnerable Versions:
1.0, 1.1.1
Timeline
Official Publish:
December 4th, 2025
Last Modified:
December 5th, 2025
Added to House:
July 22nd, 2026