Executive brief
NetScaler ADC and Gateway appliances are used to provide secure remote access to corporate applications and networks. A vulnerability in these systems could allow a user's session to be incorrectly mixed with another user's session. This could result in unauthorized access to sensitive data or the ability for one user to perform actions on behalf of another.
Technical details
A race condition (CWE-362) exists in NetScaler ADC and NetScaler Gateway appliances. The vulnerability is triggered when the appliance is configured as a Gateway (supporting SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. This flaw in concurrent execution using shared resources leads to 'User Session Mixup,' where session data or identities may be incorrectly associated between different users. An authenticated attacker could potentially exploit this timing issue to gain access to another user's session, compromising confidentiality and integrity. NetScaler has assigned a CVSS 4.0 score of 7.7, indicating a high severity impact.
Affected products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
Timeline
- 2026-03-23: disclosed
- 2026-03-23: advisory: Original advisory published by NetScaler/Citrix