Citrix Workspace
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Citrix Workspace.
By the Year
In 2026 there have been 0 vulnerabilities in Citrix Workspace. Last year, in 2025 Workspace had 1 security vulnerability published. Right now, Workspace is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 7.80 |
| 2024 | 5 | 7.46 |
| 2023 | 3 | 6.27 |
| 2022 | 1 | 7.80 |
| 2021 | 1 | 7.80 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 9.80 |
It may take a day or so for new Workspace vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Citrix Workspace Security Vulnerabilities
Citrix Workspace App Windows LPE: Local User Attains SYSTEM Privileges
CVE-2025-4879
7.8 - High
- June 17, 2025
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Low-Priv Escalation in Citrix Workspace app for Windows (CVE-2024-7890)
CVE-2024-7890
7.3 - High
- September 11, 2024
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2024-7889 Local Priv Escal in Citrix Workspace App (Windows)
CVE-2024-7889
7.3 - High
- September 11, 2024
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Citrix Workspace App: GACS Policy Bypass in HTML5
CVE-2024-6148
8.8 - High
- July 10, 2024
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
Citrix Workspace App Windows LPE CVE-2024-6286
CVE-2024-6286
7.8 - High
- July 10, 2024
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Redirection Attack in Citrix Workspace App for HTML5 (CVE-2024-6149)
CVE-2024-6149
6.1 - Medium
- July 10, 2024
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
Citrix Workspace Linux Session Hijack via Local User
CVE-2023-24486
5.5 - Medium
- July 10, 2023
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
Citrix Workspace App: System Privilege Escalation (CVE202324485)
CVE-2023-24485
7.8 - High
- February 16, 2023
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
AuthZ
Directory Traversal: Unauthorized Log File Write Vulnerability
CVE-2023-24484
5.5 - Medium
- February 16, 2023
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed
CVE-2022-21825
7.8 - High
- February 09, 2022
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially
CVE-2021-22907
7.8 - High
- May 27, 2021
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVE-2019-11634
9.8 - Critical
- May 22, 2019
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Citrix Workspace or by Citrix? Click the Watch button to subscribe.