CVE-2025-66391: n/a
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
AI Analysis
Technical Summary
This vulnerability allows an attacker with read-only access to Citrix Cloud to trigger the start of workflows that should require write permissions. Specifically, the system may send a one-time password to an email address controlled by the attacker when attempting to reset a user account password. This behavior could potentially be leveraged to interfere with account security processes. The vulnerability is documented without a CVSS score or known exploits in the wild, and no remediation level or patch information is available.
Potential Impact
An attacker with read-only access can initiate sensitive workflows such as password resets, causing the system to send one-time passwords to attacker-controlled email addresses. This could undermine account security by facilitating unauthorized password resets or other write operations indirectly. The exact scope and exploitability are not detailed, and no known exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is currently documented. Organizations should monitor vendor communications for updates and consider restricting read-only account capabilities until a fix is available.
CVE-2025-66391: n/a
Description
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability allows an attacker with read-only access to Citrix Cloud to trigger the start of workflows that should require write permissions. Specifically, the system may send a one-time password to an email address controlled by the attacker when attempting to reset a user account password. This behavior could potentially be leveraged to interfere with account security processes. The vulnerability is documented without a CVSS score or known exploits in the wild, and no remediation level or patch information is available.
Potential Impact
An attacker with read-only access can initiate sensitive workflows such as password resets, causing the system to send one-time passwords to attacker-controlled email addresses. This could undermine account security by facilitating unauthorized password resets or other write operations indirectly. The exact scope and exploitability are not detailed, and no known exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is currently documented. Organizations should monitor vendor communications for updates and consider restricting read-only account capabilities until a fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-11-28T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a32a8820b89be688863511c
Added to database: 6/17/2026, 2:00:34 PM
Last enriched: 6/17/2026, 2:45:40 PM
Last updated: 6/17/2026, 5:23:34 PM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.