
CVE-2026-8451
A pre-authentication memory disclosure vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway configured as a SAML Identity Provider (IdP).
CVE-2026-8451 is a High-Severity memory disclosure vulnerability caused by an Out-of-Bounds Read (CWE-125) during SAML Identity Provider request processing.
An unauthenticated attacker can send specially crafted SAML requests to trigger a memory overread, potentially exposing sensitive process memory.
| Property | Value |
|---|---|
| CVE | CVE-2026-8451 |
| Severity | 🔴 High |
| CVSS | 8.8 |
| CWE | CWE-125 |
| Attack Vector | Network |
| Authentication | ❌ None |
| User Interaction | ❌ None |
| Affected Service | /saml/login |
| Impact | Memory Disclosure |
| Patch Available | ✅ Yes |
| 🔐 | 🍪 | 🧠 | 📍 | ⚠️ |
|---|---|---|---|---|
| Session Data | Auth Tokens | Process Memory | Memory Addresses | DoS |
Successful exploitation may expose:
Incoming SAML Request
│
▼
Improper XML Validation
│
▼
Out-of-Bounds Read
│
▼
Memory Disclosure
| Product | Status |
|---|---|
| NetScaler ADC | ✅ Affected |
| NetScaler Gateway | ✅ Affected |
Only systems configured as a SAML Identity Provider (IdP) are vulnerable.
| Release Branch | Fixed Version |
|---|---|
| 14.1 | 14.1-72.61 |
| 13.1 | 13.1-63.18 |
| FIPS | Latest |
| NDcPP | Latest |
✔ Upgrade Immediately
✔ Disable SAML IdP if Unused
✔ Restrict Internet Exposure
✔ Monitor /saml/login
✔ Review Authentication Logs
✔ Deploy IDS/IPS Signatures
✔ Detect Memory Disclosure Attempts
Monitor for:
/saml/login| Public Research | Proof of Concept | In-the-Wild |
|---|---|---|
| ✅ Available | 🟡 Partial | ❌ No Confirmed Reports |
[+] CVE-2026-8451 PoC - Ashraf Zaryouh (0xBlackash)
[+] Target: https://target.example.com
[+] Starting memory overread attempts...
[-] Attempt 1/12 (padding 476) - No leak
[-] Attempt 2/12 (padding 508) - No leak
[+] SUCCESS! Memory leak detected (padding: 540)
Leaked bytes: 312
Hexdump:
66 6f 6f 62 61 72 00 00 de de de de de de de de |foobar..........|
0d 0a 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e |..Authentication|
3a 20 53 65 73 73 69 6f 6e 49 44 3d 78 78 78 78 |: SessionID=xxxx|
de de de de de de de de 0a 0d 55 73 65 72 2d 41 |..........User-A|
67 65 6e 74 3a 20 4d 6f 7a 69 6c 6c 61 2f 35 2e |gent: Mozilla/5.|
... (more binary data)
ASCII preview:
foobar......Authentication: SessionID=xxxx......User-Agent: Mozilla/5.
This repository is provided for educational, defensive, and cybersecurity research purposes only. It does not include exploit code or instructions for unauthorized access. Always conduct security testing with proper authorization.
If you found this repository useful, consider giving it a ⭐.
Stay Secure • Patch Early • Defend Continuously