A vulnerability, which was classified as problematic, has been found in Ping Identity PingIDM up to 7.2.2/7.3.1/7.4.1/7.5.0. This affects an unknown function. The manipulation leads to insufficient granularity of access control.

This vulnerability is traded as CVE-2025-20628. It is possible to initiate the attack remotely. There is no exploit available.