Executive brief
Citrix NetScaler ADC and Gateway appliances, which are used to manage network traffic and provide secure remote access, contain a vulnerability that could allow an unauthorized person to read sensitive files. This issue occurs when management access is enabled on specific network interfaces. An attacker could exploit this to gain access to internal system information, potentially leading to further security breaches or data exposure.
Technical details
An unauthenticated arbitrary file read vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway. The flaw is present when management access is enabled on the NetScaler IP (NSIP), Cluster Management IP, or Subnet IP (SNIP). A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the management interface, allowing them to read arbitrary files from the underlying filesystem. This could result in the disclosure of sensitive configuration data or system credentials. Users are advised to apply the latest security updates from Citrix and restrict management access to trusted networks.
Affected products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
Timeline
- 2026-06-30: advisory: Initial disclosure date