Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

By Guru Baran
Publication Date: 2026-07-18 08:41:00

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines.

The more severe issue, tracked as CVE-2026-53565, carries a CVSS v4.0 base score of 8.5 and stems from improper privilege management (CWE-269). The flaw allows a standard, low-privileged user with local access to escalate privileges to SYSTEM level, the highest privilege tier on Windows systems.

This vulnerability affects both Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows simultaneously.

The vector string CVSS:4.0 indicates the attack requires only local access, low complexity, and low privileges, with no user interaction needed, while resulting in complete compromise of confidentiality, integrity, and availability.

The second flaw, CVE-2026-53566, is rated 6.8 on the CVSS…