Identity CVE · Other
CVE-2025-55129Ivanti EPMM addUser validation bypass and impersonation
critical
Product: Ivanti Endpoint Manager Mobile (EPMM)Vendor: IvantiDisclosed: 2025-08-19Status: PatchedNVD ↗
What broke
Ivanti EPMM did not validate the addUser path the way the rest of the admin API did. An attacker could create a user or impersonate one. Ivanti patched. Ivanti MDM products have a long KEV history even when a specific ID is not yet listed.
Why it matters
EPMM decides which devices are trusted for Conditional Access and which users get email. Impersonation there bypasses the device-trust story your IdP thinks it is enforcing.
What to do
- Patch EPMM. Confirm every appliance, including DR.
- Review users created through the API around the disclosure window.
- Do not expose EPMM admin to the internet. Pair device compliance with phishing-resistant MFA, not instead of it.
Sources
- NVD: CVE-2025-55129
- Ivanti security advisory
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.