
CVE-2025-20628 An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure … https://www.cve.org/CVERecord?id=CVE-2025-20628
Post summary
The statement announces an access‑control weakness in PingIDM, noting that administrators cannot properly configure permissions due to granularity limits; it provides basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

