Skip to finding
§
High
Edge
Confirmed
CVE-2026-19490

A single unsigned SAML GET can forge a NetScaler Gateway or AAA session.

The affected Redirect-binding path defeats the default unsigned-assertion policy.

Affects

Customer-managed NetScaler ADC and NetScaler Gateway appliances exposing SAML-authenticated Gateway or AAA virtual servers.

What it enables

Unauthenticated session forgery on a SAML-configured NetScaler Gateway or AAA virtual server

Reach the exposed Gateway or AAA virtual server and collect the pre-authentication SAML redirect values→↓Send an unsigned attacker-built assertion to GET /cgi/samlauth→↓The Redirect-binding parser clears strict signature enforcement and misinterprets the default unsigned-assertion policy→↓NetScaler constructs an authenticated session from the assertion fields
Why this matters

This is a code-backed authentication bypass: a reachable SAML endpoint can construct a session from attacker-controlled assertion fields without a signed assertion.

Detail, proof-of-concept code and 4 sources
Required access

Internet reachability to an affected NetScaler Gateway or AAA virtual server with a SAML action bound

Affected versions

NetScaler ADC and Gateway 14.1 before 14.1-73.32, NetScaler ADC and Gateway 13.1 before 13.1-63.21, NetScaler ADC 14.1-FIPS before 14.1-73.32, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.277

Proof of concept

Public exploit code →

The caller collects the pre-authentication redirect values, sends an attacker-built unsigned assertion to /cgi/samlauth, and receives a session after the parser clears strict signature enforcement.

Public code performs the forgery. Citrix has fixed builds, but pre-fix images remain accepted; matching probes do not yet establish successful compromise.

Evidence
Citrix confirms the alternate-path authentication bypass, affected configurations, versions, and fixed buildsPublic repository documents the parser behavior and contains exploit code for unsigned-session forgeryTelemetry confirms matching probes but not successful compromise
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026