← Vulnerability feed

Vulnerability record · CVE-2020-8209 · published 17 August 2020

CVE-2020-8209: Citrix XenMobile Server improper access control allows arbitrary file read

Citrix · Xenmobile Server

Citrix XenMobile Server contains an improper access control flaw, classified as path traversal (CWE-22), that lets an attacker read arbitrary files. It affects multiple 10.x release trains before their respective rollup patches. Because the exposed data is read from the server itself, it can leak configuration and credential material used by the mobile device management platform.

7.5 CVSS 3.1 High EPSS 49% · top 1.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file read with a CVSS of 7.5 and very high EPSS, though no confirmed exploitation or KEV listing.

What it is

Citrix XenMobile Server contains an improper access control flaw, classified as path traversal (CWE-22), that lets an attacker read arbitrary files. It affects multiple 10.x release trains before their respective rollup patches. Because the exposed data is read from the server itself, it can leak configuration and credential material used by the mobile device management platform.

Impact

An unauthenticated attacker can read arbitrary files on the XenMobile Server, exposing configuration, secrets or other sensitive data stored on the host. This is a confidentiality-only impact; there is no evidence in the record of code execution or data modification.

Attack surface

The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the XenMobile Server interface can attempt it. No authentication is required per the CVSS vector.

Exploitation

The record shows no CISA KEV listing and no exploit-tagged references; only vendor advisories are cited. EPSS is high at roughly 0.49 probability over 30 days (98.8th percentile), indicating elevated likelihood of attempted exploitation despite the absence of confirmed in-the-wild use.

What to do

  • Apply the Citrix rollup patches: 10.12 RP2, 10.11 RP4, 10.10 RP6, or 10.9 RP5, per vendor advisory CTX277457.
  • If patching cannot be done immediately, restrict network access to the XenMobile Server management interface to trusted hosts only.
  • Rotate any credentials, tokens or certificates that may have been stored in files readable on the server.
  • Monitor Citrix advisory CTX277457 for updated guidance and confirm the deployed build against the fixed rollup levels.

Detection

  • Review web server and application logs for path traversal patterns (../, encoded variants) against XenMobile endpoints.
  • Alert on unexpected outbound or internal requests to file-serving paths from unauthenticated clients.
  • Baseline and monitor file access on the XenMobile host for reads of configuration or credential files by the web service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8211Citrix xenmobile server command injection vulnerabilityImproper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 an…EPSS 1.5%9.8CVE-2020-8212Citrix xenmobile server incorrect authorization vulnerabilityImproper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and …EPSS 1.6%9.8CVE-2018-10653Citrix xenmobile server xml external entity (xxe) vulnerabilityThere is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.EPSS 6.8%9.8CVE-2018-10648Citrix xenmobile server unrestricted file upload vulnerabilityThere are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.EPSS 1.2%9.1CVE-2018-18571Citrix xenmobile server improper authentication vulnerabilityAn Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patc…EPSS 2.6%8.8CVE-2021-44519Citrix xenmobile server path traversal vulnerabilityIn Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.EPSS 2.8%8.8CVE-2021-44520Citrix xenmobile server command injection vulnerabilityIn Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root p…EPSS 5.7%8.1CVE-2018-10654Citrix xenmobile server deserialization of untrusted data vulnerabilityThere is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2020-8209), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.