CVE-2025-66391

HIGH

Citrix Cloud through 2025-11-10 - Authenticated Workflow Bypass via Read-Only Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-66391. PoCs published by mandeepsohal.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-66391, an authorization bypass vulnerability in Citrix Cloud where read-only users can trigger workflows for write operations, such as sending OTPs to attacker-controlled emails. The writeup includes a step-by-step proof of concept, impact analysis, and mitigation recommendations.

Description

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.

Exploits (1)

github WRITEUP
by mandeepsohal · poc
https://github.com/mandeepsohal/CVE-2025-66391

This repository provides a detailed technical analysis of CVE-2025-66391, an authorization bypass vulnerability in Citrix Cloud where read-only users can trigger workflows for write operations, such as sending OTPs to attacker-controlled emails. The writeup includes a step-by-step proof of concept, impact analysis, and mitigation recommendations.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Citrix Cloud through 2025-11-10
Auth required
Prerequisites: read-only access to Citrix Cloud · ability to intercept and manipulate server responses
devstral-2 · analyzed Jun 17, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Published Jun 17, 2026
Tracked Since Jun 17, 2026