CVE-2025-66391
HIGHCitrix Cloud through 2025-11-10 - Authenticated Workflow Bypass via Read-Only Access
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-66391. PoCs published by mandeepsohal.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-66391, an authorization bypass vulnerability in Citrix Cloud where read-only users can trigger workflows for write operations, such as sending OTPs to attacker-controlled emails. The writeup includes a step-by-step proof of concept, impact analysis, and mitigation recommendations.
Description
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2025-66391, an authorization bypass vulnerability in Citrix Cloud where read-only users can trigger workflows for write operations, such as sending OTPs to attacker-controlled emails. The writeup includes a step-by-step proof of concept, impact analysis, and mitigation recommendations.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H