Authentication bypass using an alternate path or channel in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-19490
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to authentication bypass using an alternate path in the Gateway or AAA virtual server authentication functionality when handling authentication requests. A remote attacker can use an alternate path to bypass authentication.
The issue is exposed only on appliances configured as a Gateway or an AAA virtual server, and on certain versions only when configured with a SAML action.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-19490
Citrix NetScaler Gateway - addressed in versions 13.1-63.21, 14.1-73.32