Loading
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Use CWE-288, Ivanti vendor hub and Endpoint Manager Mobile product page to widen CVE-2025-4427 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-1340, CVE-2026-1281 and CVE-2025-4428 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.