CVE-2026-10816
EUVD-2026-4031030.06.2026, 13:17
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabledEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| citrix | netscaler_application_delivery_controller | 𝑥 < 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | 𝑥 < 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | 14.1 ≤ 𝑥 < 14.1-72.61 |
| citrix | netscaler_application_delivery_controller | 14.1-66.68 |
| citrix | netscaler_gateway | 13.1 ≤ 𝑥 < 13.1-63.18 |
| citrix | netscaler_gateway | 14.1 ≤ 𝑥 < 14.1-72.61 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-73 - External Control of File Name or PathThe software allows user input to control or influence paths or file names that are used in filesystem operations.
- CWE-610 - Externally Controlled Reference to a Resource in Another SphereThe product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.