A vulnerability, which was classified as critical, was found in CyberArk Endpoint Privilege Manager 24.7.1. Affected is an unknown function. The manipulation of the argument X-Forwarded-For leads to authentication bypass by spoofing.
This vulnerability is traded as CVE-2025-22271. It is possible to launch the attack remotely. There is no exploit available.