Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges

Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges

By Tamilselvan
Publication Date: 2026-07-18 04:15:00

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, the more severe of which allows a standard user to escalate privileges to SYSTEM level.

The flaws are tracked as CVE-2026-53565 and CVE-2026-53566, detailed in Citrix Security Bulletin CTX696734, published on July 14, 2026.

Citrix Secure Access Client Flaw

The higher-severity flaw, CVE-2026-53565, stems from improper privilege management (CWE-269) and carries a CVSS v4.0 base score of 8.5 (High). It affects both Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.

An attacker only needs standard user access on the local machine to exploit this vulnerability; no user interaction or elevated privileges are required beforehand.

Successful exploitation grants the attacker full SYSTEM-level control, effectively handing over complete control of the compromised host’s…