Executive brief
A security vulnerability has been identified in Citrix software used for secure remote access and device health checks on Windows computers. An attacker who already has basic access to a user's computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the system, bypass security controls, or access sensitive data.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the Citrix Secure Access Client and Citrix Endpoint Analysis Client for Windows. The flaw allows a local, authenticated user with low privileges to escalate their permissions to a higher level, potentially gaining full system access. The vulnerability is triggered locally and does not require user interaction or complex configurations. Citrix has released updates to address this issue, and users are advised to upgrade to Secure Access Client version 26.6.1.20 or later, and Endpoint Analysis Client version 26.5.1.7 or later.
Affected products
- Citrix Secure Access Client for Windows before 26.6.1.20
- Citrix Citrix Endpoint Analysis Client for Windows before 26.5.1.7
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory