CVE-2025-25231: Omnissa Workspace One UEM

High severity, CVSS 7.5. EPSS: 23% chance of exploitation in the next 30 days.

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

Affected products

  • Omnissa Omnissa Workspace One UEM: up to and including 24.10.0.10; up to and including 24.6.0.34; up to and including 24.2.0.29; up to and including 23.10.0.49

Published 2025-08-11. Last modified 2026-06-17.