CVE-2025-25231 is a pre-authentication secondary-context path-traversal vulnerability in the DevicesGateway component of Omnissa Workspace ONE UEM. The unauthenticated SystemAppMetadataV1Controller accepted an attacker-controlled packageId value that could be overridden through a query parameter. That value was incorporated into an internally routed resource request without sufficient validation. The gateway then resolved the resource against its internal routing configuration and attached administrator-level authentication material, including bearer tokens, API keys, tenant context, and other internal headers, to the secondary request. An unauthenticated attacker could thereby cause authenticated requests to arbitrary GET-based UEM APIs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pre-authentication path traversal and authentication-bypass vulnerability in Omnissa Workspace ONE UEM. The flaw abuses secondary-context request routing to access internal APIs with automatically applied administrator credentials, enabling unauthenticated disclosure of sensitive UEM data. The described kill chain can enumerate administrator accounts and, combined with weak passwords and a separate hardcoded-key issue, potentially lead to remote code execution.
A critical path traversal vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) that allows unauthenticated attackers to bypass authentication, disclose sensitive information, and potentially achieve Remote Code Execution by exploiting improper validation of the packageId parameter in the SystemAppMetadataV1Controller.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.