Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. (CVE-2026-78547)
An out-of-bounds write vulnerability exists in Citrix Workspace app for Windows, affecting versions before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. This vulnerability could potentially allow unauthorized modification of memory, which may impact the application's stability or security. The issue is classified as medium severity based on available data. No official patch or remediation information is provided in the source data.
AI Analysis
Technical Summary
CVE-2026-78547 describes an out-of-bounds write vulnerability in Citrix Workspace app for Windows. The flaw involves writing data outside the intended memory boundaries, which can cause memory corruption. The affected versions are those prior to 2603.11 CR, 2507.1 LTSR CU3, and LTSR 2607. The vulnerability is classified under CWE-787. The CVSS vector indicates a medium severity with partial attack complexity and limited privileges required, but no user interaction needed. No exploits have been reported in the wild.
Potential Impact
Successful exploitation of this vulnerability could result in memory corruption, potentially leading to application crashes or other unintended behavior. The CVSS vector suggests a medium severity impact with high integrity and availability impact, but no confirmed active exploitation is reported.
Mitigation Recommendations
No explicit patch or remediation information is provided in the source data. Users should upgrade to versions 2603.11 CR, 2507.1 LTSR CU3, or LTSR 2607 or later once available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. (CVE-2026-78547)
Description
An out-of-bounds write vulnerability exists in Citrix Workspace app for Windows, affecting versions before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. This vulnerability could potentially allow unauthorized modification of memory, which may impact the application's stability or security. The issue is classified as medium severity based on available data. No official patch or remediation information is provided in the source data.
CVSS v4.0
Affected software
pkg:github/citrix/workspace-app-windowsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-78547 describes an out-of-bounds write vulnerability in Citrix Workspace app for Windows. The flaw involves writing data outside the intended memory boundaries, which can cause memory corruption. The affected versions are those prior to 2603.11 CR, 2507.1 LTSR CU3, and LTSR 2607. The vulnerability is classified under CWE-787. The CVSS vector indicates a medium severity with partial attack complexity and limited privileges required, but no user interaction needed. No exploits have been reported in the wild.
Potential Impact
Successful exploitation of this vulnerability could result in memory corruption, potentially leading to application crashes or other unintended behavior. The CVSS vector suggests a medium severity impact with high integrity and availability impact, but no confirmed active exploitation is reported.
Mitigation Recommendations
No explicit patch or remediation information is provided in the source data. Users should upgrade to versions 2603.11 CR, 2507.1 LTSR CU3, or LTSR 2607 or later once available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cmf8-hqjg-89gj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-78547"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa4a03355bf5e2cf5a873f8
Added to database: 09/12/2026, 00:43:31 UTC
Last enriched: 09/12/2026, 01:27:25 UTC
Last updated: 09/12/2026, 03:01:22 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.