{"id":"CVE-2025-66391","title":"In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker a…","summary":"In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker a…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"published":"2026-06-17","updated":"2026-10-05","sourceUpdated":"2026-10-05T16:10:00.443","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66391","references":[{"url":"https://citrix.cloud.com/","label":"cve@mitre.org"},{"url":"https://github.com/mandeepsohal/CVE-2025-66391/blob/main/Exploit.md","label":"cve@mitre.org"},{"url":"https://github.com/mandeepsohal/CVE-2025-66391/blob/main/Exploit.md","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00383,"epssPercentile":0.30035,"exploits":{"github":1,"githubRepos":["https://github.com/mandeepsohal/CVE-2025-66391"],"checkedAt":"2026-10-05T16:26:33.434Z"},"exploitAvailable":true,"ingestedAt":"2026-10-05T16:25:58.375Z","slug":"CVE-2025-66391","body":"## Overview\n\nIn Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}