CVE-2025-4427 is an authentication bypass vulnerability in the API component of Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core. An insecure Spring Framework implementation allows request validation to occur before authentication enforcement. Crafted API requests can therefore reach protected functionality without valid credentials. The vulnerable feature-usage request processing validates the format parameter before authenticating the requester. Affected branches include 11.12.0.4 and earlier, 12.3.0.1 and earlier, 12.4.0.1 and earlier, and 12.5.0.0 and earlier. Chaining this bypass with the separate code-injection vulnerability CVE-2025-4428 enables unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module targeting Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. The exploit leverages an authentication bypass (CVE-2025-4427) and an expression language injection (CVE-2025-4428) to achieve unauthenticated remote code execution via a vulnerable web API endpoint. The main exploit file is written in Ruby and is structured as a standard Metasploit module, including auto-check capabilities and options for SSL and target URI configuration. The exploit works by sending a specially crafted payload to the '/mifs/rs/api/v2/featureusage' endpoint, injecting an expression that executes arbitrary Python code as the 'tomcat' user. The module includes a check method that attempts to execute the 'id' command to verify vulnerability. The payload is encoded in base64 and executed using Python on the target. The exploit is operational and provides remote code execution without authentication, making it a significant risk for affected systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
236 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass in Ivanti EPMM caused by validating the format parameter at /mifs/rs/api/v2/featureusage before authenticating the requester. Combined with CVE-2025-4428, it enables unauthenticated remote code execution. A public exploit chain was published on May 15, 2025, when in-the-wild exploitation also began. CrowdSec reports 865 unique source IPs since May 22, 2025, and 3,978 matching signals during June 24–September 20, 2026; these signals do not establish successful compromise. Affected branch versions are 11.12.0.4, 12.3.0.1, 12.4.0.1, 12.5.0.0 and earlier. Initial fixes were released on May 13, 2025, in 11.12.0.5, 12.3.0.2, 12.4.0.2 and 12.5.0.1. Restricting API access mitigates exposure, but patching does not remove existing implants or restore compromised credentials.
Ivanti EPMMの脆弱性として例示され、BOD 26-04では悪用確認と自動化可能性により最優先対応対象になる事例。
Authentication bypass vulnerability in the Ivanti EPMM API caused by an insecure Spring Framework implementation; used as the first step in a chained attack with CVE-2025-4428.
A critical Ivanti EPMM vulnerability mentioned in a historical timeline of prior exploitation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.