
Citrix NetScaler SAML प्रमाणीकरण बायपास CVE-2026-19490 का सुरक्षित रूप से पता लगाएं
CVE-2026-19490 के लिए एक सुरक्षित, अनऑथेंटिकेटेड वल्नरेबिलिटी जाँच, जो Citrix NetScaler ADC / NetScaler Gateway SAML सर्विस-प्रोवाइडर पथ में प्री-ऑथेंटिकेशन ऑथेंटिकेशन बायपास है
(CTX696939,
प्रकाशित 2026-08-19)। CWE-288, CVSS v4.0 9.3
(AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)। JPMorgan Chase पेनिट्रेशन टेस्टिंग टीम के Samarth Vashisht द्वारा रिपोर्ट किया गया।
अप्लायंस SAML रिस्पॉन्स के RelayState पैरामीटर को base64-डिकोड करता है और, जब प्लेनटेक्स्ट ctx= से शुरू होता है, तो शेष भाग को nFactor कॉन्टेक्स्ट डिसेरिएलाइज़र को सौंप देता है। अनपैच्ड बिल्ड पर एक डिसेरिएलाइज़ेशन विफलता त्रुटि के बजाय डिकोड किए गए RelayState की लंबाई को रिक्वेस्ट के आंतरिक डिस्पोज़िशन कोड के रूप में प्रसारित कर देती है, इसलिए एक अनऑथेंटिकेटेड हमलावर केवल यह चुनकर कि RelayState कितना लंबा है, यह तय करता है कि अप्लायंस आगे कौन-सी आंतरिक शाखा लेगा। कुछ शाखाएँ एक वास्तविक Gateway सेशन बनाती हैं; अन्य पैकेट इंजन को क्रैश कर देती हैं और अप्लायंस को रीस्टार्ट कर देती हैं। यह स्क्रिप्ट दोनों में से कुछ नहीं करती — यह वह एक लंबाई भेजती है जिसे सत्यापित किया गया है कि कोई सेशन नहीं बनाती और पैकेट इंजन को अछूता छोड़ती है, और प्रति लक्ष्य एक ही प्रश्न का उत्तर देती है: क्या यह अप्लायंस वल्नरेबल है? VULNERABLE के अलावा कोई परिणाम स्वयं में स्वच्छता का प्रमाण पत्र नहीं है।
# single target
./cve_2026_19490_check.py https://gateway.example.com
# a specific Gateway or AAA virtual server
./cve_2026_19490_check.py https://gateway.example.com:9443
# several targets; the scheme defaults to https://
./cve_2026_19490_check.py gw-a.example.com gw-b.example.com:9443
# scan a list, one target per line ('#' comments allowed), compact output
./cve_2026_19490_check.py -f targets.txt --brief
# machine-readable output for pipelines
./cve_2026_19490_check.py -f targets.txt --json > results.json
Python 3.8+, केवल स्टैंडर्ड लाइब्रेरी — कोई थर्ड-पार्टी पैकेज नहीं।
टूल को Gateway या AAA वर्चुअल सर्वर पर इंगित करें, मैनेजमेंट इंटरफ़ेस पर नहीं। एक्सपोज़र प्रति वर्चुअल सर्वर होता है, इसलिए कई VIP वाले अप्लायंस के प्रत्येक को परखा जाना चाहिए। प्रोब में एक कठोर सुरक्षा लिफ़ाफ़ा है — एक सत्यापित RelayState लंबाई, कभी स्वीप नहीं — जिसे क्या इसे चलाना सुरक्षित है? में बताया गया है।
| फ़्लैग | विवरण |
|---|---|
TARGET | एक या अधिक [https://]HOST[:PORT] लक्ष्य; स्कीम डिफ़ॉल्ट रूप से https:// है |
-f, --targets-file FILE | किसी फ़ाइल से लक्ष्य पढ़ें (प्रति पंक्ति एक; # टिप्पणियाँ) |
--timeout SECS | प्रति-रिक्वेस्ट टाइमआउट (डिफ़ॉल्ट: 15) |
--workers N | समवर्ती लक्ष्य (डिफ़ॉल्ट: 16); आउटपुट इनपुट क्रम में रहता है |
-b, --brief | प्रति लक्ष्य एक संरेखित पंक्ति — कई होस्ट स्कैन करने के लिए आदर्श |
--json | संरचित JSON उत्पन्न करें, जिसमें प्रति लक्ष्य भेजी गई प्रत्येक रिक्वेस्ट शामिल हो |
--no-color | रंगीन आउटपुट अक्षम करें (NO_COLOR और गैर-TTY का भी सम्मान करता है) |
एक वल्नरेबल अप्लायंस (डिफ़ॉल्ट दो-पंक्ति आउटपुट)। [!] मार्कर और VULNERABLE TTY पर लाल रेंडर होते हैं:
$ ./cve_2026_19490_check.py https://gateway.example.com:9443
[!] https://gateway.example.com:9443: VULNERABLE [internal-error-43524]
HTTP 500 / 43524: the decoded RelayState length was propagated as the internal error, so the CTX696939 fix is absent
एक पैच्ड अप्लायंस:
$ ./cve_2026_19490_check.py https://vpn.example.com
[+] https://vpn.example.com: PATCHED [fixed-error-returned]
HTTP 200 "Malformed Assertion": the fixed error was returned on the path this probe reached, so the CTX696939 fix is present (>= 13.1-63.21 / 14.1-73.32)
फ़ॉल्स-पॉज़िटिव गार्ड का सक्रिय होना। प्रोब और समान-लंबाई वाला कंट्रोल दोनों ने अनपैच्ड सिग्नल लौटाया, इसलिए उत्तर इस पर निर्भर नहीं करता कि क्या भेजा गया था और निर्णायक दिखने वाला उत्तर वापस ले लिया जाता है:
$ ./cve_2026_19490_check.py https://sp-strict.example.com
[?] https://sp-strict.example.com: INCONCLUSIVE [flat-response]
the probe and the same-length control both answered HTTP 500 / 43524, so the reply does not depend on what was sent and the fix was never exercised; unknown, not patched
एक एस्टेट को स्वीप करना (--brief)। दो gateway.example.com पंक्तियाँ एक ही अप्लायंस पर SP और केवल-IdP वर्चुअल सर्वर हैं — दोनों उत्तर देते हैं, जो एक कॉन्फ़िगरेशन-पूर्वशर्त जाँच नहीं कर पाती:
$ ./cve_2026_19490_check.py -f targets.txt --brief; echo "exit: $?"
VULNERABLE https://gateway.example.com:9443 internal-error-43524
VULNERABLE https://gateway.example.com:9444 internal-error-43524
PATCHED https://vpn.example.com fixed-error-returned
INCONCLUSIVE https://sp-strict.example.com flat-response
UNAFFECTED https://lb.example.com no-saml-endpoint
ERROR https://www.example.com not-identified
exit: 1
मशीन-पठनीय आउटपुट (--json)। प्रत्येक रिक्वेस्ट शामिल है, इसलिए किसी निष्कर्ष को भरोसे के बजाय साक्ष्य से पुनः प्राप्त किया जा सकता है। कंट्रोल को उसके स्वयं के निर्णय के रूप में नहीं, बल्कि प्रोब से उसके संबंध द्वारा दर्ज किया जाता है, क्योंकि पैच्ड बिल्ड जैसा पढ़ने वाला कंट्रोल प्रत्येक बिल्ड पर अपेक्षित परिणाम है:
$ ./cve_2026_19490_check.py https://gateway.example.com:9443 --json
[
{
"target": "https://gateway.example.com:9443",
"verdict": "VULNERABLE",
"reason": "internal-error-43524",
"detail": "HTTP 500 / 43524: the decoded RelayState length was propagated as the internal error, so the CTX696939 fix is absent",
"netscaler_indicators": [
"CSP contains citrixng://",
"CSP contains com.citrix.nsgclient://",
"CSP contains nsgcepa://",
"CSP report-uri /nscsp_violation/report_uri",
"/vpn/js/rdx/ present (HTTP 404)"
],
"attempts": [
{
"kind": "probe",
"path": "/cgi/samlauth",
"status": 500,
"state": "unpatched",
"detail": "HTTP 500 / 43524: the decoded RelayState length was propagated as the internal error"
},
{
"kind": "control",
"path": "/cgi/samlauth",
"status": 200,
"state": "differs-from-probe",
"detail": "same-length control: HTTP 200 \"Malformed Assertion\": the fixed error was returned"
}
]
}
]
हाँ। यह प्रोडक्शन और असेसमेंट उपयोग के लिए डिज़ाइन किया गया है: