CVE-2026-78547
Received Received - Intake

Out-of-bounds Write in Citrix Workspace App for Windows

Vulnerability report for CVE-2026-78547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Citrix Systems, Inc.

Description

Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
citrix workspace_app to 2603.11 (exc)
citrix workspace_app to 2507.1 (exc)
citrix workspace_app to 2607 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds write vulnerability in Citrix Workspace app for Windows. It allows an attacker with local access to write data beyond allocated memory boundaries, potentially leading to code execution or system crashes.

Detection Guidance

This vulnerability is specific to Citrix Workspace app for Windows versions before 2603.11 CR, 2507.1 LTSR CU3, and LTSR 2607. Detection requires checking the installed version of Citrix Workspace app. Use the command 'wmic product where "name like 'Citrix Workspace%'" get name, version' in Command Prompt to verify the version.

Impact Analysis

An attacker could exploit this to execute arbitrary code on your system, gain elevated privileges, or cause denial-of-service conditions. It requires local access but could lead to full system compromise if exploited.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with standards like GDPR or HIPAA. The vulnerability is an out-of-bounds write issue in Citrix Workspace app for Windows, which could potentially lead to unauthorized code execution or data corruption. However, without additional context on data handling or exposure, its specific compliance implications remain unclear.

Mitigation Strategies

Update Citrix Workspace app for Windows to version 2603.11 Current Release (CR) or later, 2507.1 LTSR CU3 or later, or LTSR 2607 or later to address the out-of-bounds write vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart