CVE-2026-78546
Received Received - Intake

Out-of-Bounds Read in Citrix Workspace Windows App

Vulnerability report for CVE-2026-78546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Citrix Systems, Inc.

Description

Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
citrix workspace_app to 2603.11 (exc)
citrix workspace_app to 2507.1 (exc)
citrix workspace_app to 2607 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in the Citrix Workspace app for Windows. It allows an attacker with local access to read memory outside the intended buffer, potentially exposing sensitive data.

Detection Guidance

Detection of this vulnerability requires checking the installed version of Citrix Workspace app for Windows. Compare the installed version against the affected versions: before 2603.11 CR, before 2507.1 LTSR CU3, or before LTSR 2607. Use the 'About' section in the Citrix Workspace app or check installed programs via Control Panel or PowerShell commands like 'Get-WmiObject -Class Win32_Product'.

Impact Analysis

An attacker could exploit this to access sensitive information on your system, such as passwords or other confidential data. It requires local access but could lead to further compromise if combined with other vulnerabilities.

Compliance Impact

The provided CVE data does not specify how this vulnerability impacts compliance with standards like GDPR or HIPAA. The vulnerability is an out-of-bounds read issue in Citrix Workspace app for Windows, which could potentially lead to unauthorized data access or information disclosure. However, explicit compliance implications are not detailed in the given context.

Mitigation Strategies

Update Citrix Workspace app for Windows to version 2603.11 Current Release (CR), 2507.1 LTSR CU3, or LTSR 2607 to address the out-of-bounds read vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart