Junglewise Threat Intelligence

CVE-2026-18751: Citrix WorkSpace App macOS arbitrary root file modification

CVE-2026-18751 · Severity: info · CVSS 5.2 · Published 2026-08-18

Vendors: Citrix.

Executive brief

Citrix WorkSpace App for macOS contains a vulnerability that allows a locally authenticated user to modify files with root privileges, potentially gaining full administrative control of the system. An attacker with standard user access could exploit this flaw to modify critical system files, install malware, or take complete control of affected Mac systems.

Technical details

This is an external control of file name or path vulnerability (CWE-73) in Citrix WorkSpace App for Mac that allows arbitrary root file modification. The vulnerability requires an attacker to have local authenticated user access to the device where the application is installed, plus user interaction. Exploitation can result in elevation of privilege from a local authenticated user to root, enabling arbitrary file modification with the highest system privileges. Affected versions are those prior to 2607; Citrix has issued a patch recommending customers update to version 2607 or later.

Affected products

  • Citrix WorkSpace App before 2607

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory
  • 2026-08-18: patched: Version 2607 and later addresses the vulnerability

References