CVE-2025-66391: High severity Citrix Citrix Cloud vulnerability
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or revoke the ability for read-only accounts to begin workflows that perform write operations (for example, prevent read-only accounts from initiating password reset workflows) until Citrix provides a fix (issue present through 2025-11-10).
Citrix Cloud allow_read_only_to_initiate_write_workflows = disabled - Compensating control
Restrict access to Citrix Cloud management functionality and password-reset endpoints to trusted administrator accounts and trusted IP ranges (firewall, VPN, or WAF) until the vendor fixes the issue (present through 2025-11-10).
- Operational
Audit recent password-reset workflow activity and OTP deliveries for signs of misuse by read-only accounts; if any accounts had OTPs sent to unknown or attacker-controlled emails, treat them as potentially compromised and rotate affected credentials and recovery contact information.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66391?
CVE-2025-66391 has a severity rating of 8.8, categorized as high risk.
How do I fix CVE-2025-66391?
To mitigate CVE-2025-66391, ensure that only authorized users have write access to workflows in Citrix Cloud.
What is the main risk associated with CVE-2025-66391?
The main risk of CVE-2025-66391 is that a user with read-only access can initiate password reset workflows, potentially allowing unauthorized account access.
Who is affected by CVE-2025-66391?
CVE-2025-66391 affects users of Citrix Cloud who have been assigned read-only access to the system.
When was CVE-2025-66391 reported?
CVE-2025-66391 was published on June 17, 2026.