Description
Out-of-bounds read vulnerability in Citirx Workspace app for Windows.

This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Published: 2026-09-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

Citrix Workspace app for Windows contains an out‑of‑bounds read flaw that allows an attacker to read memory located outside the intended buffer. This reading can expose content of the buffer or adjacent memory used by the application, potentially revealing confidential data. The flaw does not let an attacker execute code or alter the program state; it purely allows the disclosure of memory contents.

Affected Systems

Citrix Workspace app for Windows versions older than 2603.11 Current Release, older than 2507.1 LTSR CU3, and older than LTSR 2607 are affected by this issue.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest that widespread exploitation is unlikely at this time. The likely attack vector is local; remote exploitation would require additional conditions that are not documented. The primary risk is accidental leakage of sensitive information if the application runs with elevated privileges or handles privileged data.

Generated by OpenCVE AI on September 21, 2026 at 03:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Citrix Workspace app for Windows to at least version 2603.11, or apply the corresponding LTSR update.
  • Apply the principle of least privilege to limit the application’s rights to the minimum necessary.
  • Implement network segmentation or firewall rules to isolate workstations that run the Workspace app from untrusted hosts.

Generated by OpenCVE AI on September 21, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Citirx
Citirx workspace App For Windows
Vendors & Products Citirx
Citirx workspace App For Windows

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Title Out-of-Bounds Read
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Citirx Workspace App For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2026-09-11T19:34:06.655Z

Reserved: 2026-08-24T18:47:59.430Z

Link: CVE-2026-78546

cve-icon Vulnrichment

Updated: 2026-09-11T19:34:00.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T20:18:53.600

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-78546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses