Sceawere

Vulnerability Detail

CVE-2026-88774UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NetScaler Policy Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
1d ago
Vendor
Citrix NetScaler
Product
ADC
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-27T17:16:56.633Z",
  "pubdate": "2026-09-27T17:16:56.633Z",
  "executiveSummary": "This vulnerability involves a feature policy bypass in Citrix NetScaler ADC and Citrix NetScaler Gateway, stemming from the improper handling of HTTP URL-based expressions.\nThe flaw allows unauthorized actors to circumvent established security policies, potentially leading to unauthorized access or the bypass of traffic filtering controls.\nAffected products include various versions of NetScaler ADC and Gateway prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS/NDcPP.\nThe vulnerability poses a significant risk to organizational perimeter security, as an attacker can potentially reach restricted resources by crafting specific HTTP requests that the policy engine incorrectly validates or permits.\nExploitation does not necessarily require advanced administrative privileges but leverages the logic flaw in URL expression evaluation to manipulate the flow of traffic through the appliance.\nSuccessful exploitation compromises the integrity of traffic inspection mechanisms, rendering configured access control lists or security policies ineffective against specifically crafted malicious requests.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper processing and evaluation of HTTP URL-based expressions within the NetScaler ADC and Gateway security policy engine. The system fails to correctly parse or sanitize certain URL structures when enforcing configured feature policies, leading to an inconsistent state where a restricted resource becomes accessible.\nThe vulnerability specifically impacts the inspection logic that handles HTTP traffic. When a policy is configured to restrict access based on URL patterns, the parser may fail to normalize the input correctly or may be susceptible to ambiguity in URL encoding/formatting. This allows an attacker to bypass the policy engine by injecting specially crafted URL strings that the engine incorrectly identifies as compliant or outside the scope of the restriction.\nThe attack flow involves the adversary identifying an active security policy that filters traffic based on URL-based expressions. The attacker then crafts an HTTP request containing a payload designed to exploit the parsing logic discrepancy. Upon processing this request, the NetScaler component incorrectly evaluates the policy, bypassing the intended security constraint and allowing the request to proceed to the backend or restricted service.\nThis issue is not limited to a specific authentication state, as the policy bypass can often be triggered during the initial request handling phase. Because the vulnerability resides within the core traffic management component, it impacts any environment where URL-based policy filtering is deployed to govern inbound or outbound traffic.\nAffected software versions include ADC and Gateway builds prior to 14.1-73.37 and 13.1-64.23, as well as specific FIPS/NDcPP versions such as those prior to 14.1-73.37 FIPS and 13.1.37.279 FIPS/NDcPP. The exposure is network-wide for the appliance, as it affects the entry point of the infrastructure.\nPost-exploitation, the attacker gains the ability to circumvent access control policies, which can facilitate further unauthorized activities, including data exfiltration, unauthorized interaction with backend services, or the discovery of internal network topology that would otherwise be blocked by the NetScaler appliance. The failure to properly enforce these policies negates the defense-in-depth posture of the affected network segment."
}
CVE-2026-88774: NetScaler Policy Bypass Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere