Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, the more severe of which allows a standard user to escalate privileges to SYSTEM level.

The flaws are tracked as CVE-2026-53565 and CVE-2026-53566, detailed in Citrix Security Bulletin CTX696734, published on July 14, 2026.

Citrix Secure Access Client Flaw

The higher-severity flaw, CVE-2026-53565, stems from improper privilege management (CWE-269) and carries a CVSS v4.0 base score of 8.5 (High). It affects both Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.

An attacker only needs standard user access on the local machine to exploit this vulnerability; no user interaction or elevated privileges are required beforehand.

Successful exploitation grants the attacker full SYSTEM-level control, effectively handing over complete control of the compromised host’s confidentiality, integrity, and availability.

This makes the flaw particularly dangerous in enterprise environments where these clients are widely deployed for VPN and endpoint compliance checks.

The second vulnerability, CVE-2026-53566, is an out-of-bounds read issue (CWE-125) affecting only Citrix Secure Access Client for Windows. It carries a CVSS v4.0 score of 6.8 (Medium-High).

Exploitation requires standard user access and a specific precondition: the DNE (Deterministic Network Enhancer) driver must not be installed on the target system.

While less severe than the privilege escalation bug, this flaw could still expose sensitive memory contents to unauthorized processes, potentially aiding further attacks.

Affected Versions

  • Citrix Secure Access Client for Windows: versions before 26.6.1.20 (affected by both CVEs)
  • Citrix Endpoint Analysis Client for Windows: versions before 26.5.1.7 (affected by CVE-2026-53565 only)

Cloud Software Group strongly urges immediate patching. Affected customers should upgrade to:

  • Citrix Secure Access Client for Windows 26.6.1.20 or later
  • Citrix Endpoint Analysis Client for Windows 26.5.1.7 or later

No workarounds have been published for either flaw, making version upgrades the only reliable mitigation path. Citrix credited Carlos Garrido of Pentraze Cybersecurity for responsibly disclosing the issues.

Citrix has published the bulletin through its Knowledge Center. Local privilege escalation bugs like CVE-2026-53565 are especially attractive to attackers in post-exploitation scenarios.

Even if an adversary gains only low-privileged access through phishing or credential theft, a flaw like this can be the final step needed to achieve full system compromise, deploy ransomware, or move laterally across a network.

Organizations using Citrix Secure Access or Endpoint Analysis Clients should audit their deployed versions immediately and coordinate with IT teams to roll out the patched releases across all endpoints without delay.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

The post Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading