Description
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.

This issue affects WorkSpace App: 2607.
Published: 2026-08-18
Score: 5.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Citrix WorkSpace App for macOS contains an external control of file name or path vulnerability that can be leveraged to read or write arbitrary files on the system. This flaw enables an attacker to supply a crafted file path that may bypass normal access controls, potentially exposing sensitive data or modifying critical files.

Affected Systems

The vulnerability affects Citrix WorkSpace App version 2607 running on macOS. Systems using this version are exposed to the risk of arbitrary file access if an attacker can influence the file path parameter.

Risk and Exploitability

The CVSS score of 5.2 classifies this as a medium severity issue. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalogue, indicating no currently documented exploitation. The likely attack vector requires the attacker to influence input that controls the file path, suggesting that exploitation would need user interaction or privileged access to the application. While not highly likely, the medium impact warrants monitoring and patching if an update is available.

Generated by OpenCVE AI on August 18, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Citrix WorkSpace App to the latest available version that fixes the file path handling issue.
  • Configure macOS to restrict the application’s write access to critical system directories and enforce least‑privilege file permissions.
  • Implement file integrity monitoring or audit logs to detect unexpected file access attempts by the Citrix application.

Generated by OpenCVE AI on August 18, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix workspace App
Vendors & Products Citrix
Citrix workspace App

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
Title Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Citrix Workspace App
cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2026-08-18T13:40:55.355Z

Reserved: 2026-08-03T23:06:10.019Z

Link: CVE-2026-18751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:20.730

Modified: 2026-08-18T13:17:20.730

Link: CVE-2026-18751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses
  • CWE-73

    External Control of File Name or Path