CVE-2026-3055: Citrix NetScaler SAML IDP Memory Overread — Technical Analysis & Remediation
Technical root cause and active exploitation telemetry for the Citrix NetScaler SAML session memory overread flaw.
CVE-2026-3055
Severity: CVSS 9.4
Status: ⚠️ Actively Exploited In The Wild
Target Component: Citrix NetScaler ADC & Gateway SAML IDP
← Back to the June 4 Security Roundup
Overview
CVE-2026-3055 is an out-of-bounds memory read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway when configured as a SAML Identity Provider (SAML IDP). An unauthenticated attacker can send crafted HTTP requests to the /saml/login endpoint to leak memory from the previous request, potentially exposing session tokens, credentials, or cryptographic material. CVSS v3.1 base score: 9.3 (Critical). CISA added it to the KEV catalog on March 30, 2026; Fortinet confirmed large-scale active exploitation in May 2026.
Affected Versions
- NetScaler ADC and Gateway < 14.1-43.12
- NetScaler ADC and Gateway 13.1 < 13.1-57.10
- NetScaler ADC and Gateway 13.0 (end of life – no patch; upgrade required)
Vulnerability Details
The vulnerability occurs in the SAML IDP handler within nsppe. When processing the /saml/login endpoint, the code checks for the presence of the wctx query parameter but does not validate that it contains a value (it may be present as a bare wctx key without an = sign). In this case, the handler attempts to access the associated buffer with an incorrect offset, causing an out-of-bounds read of residual memory from a previous HTTP request.
Attack Chain
- Enumerate SAML IDP: Probe for SAML IDP mode via
GET /cgi/GetAuthMethods. Response includes"saml"in the auth methods array if the appliance is configured as a SAML IDP. - Trigger memory leak: Send
GET /saml/login?wctx HTTP/1.1(note:wctxwithout=value). The NSC_TASS handler reads stale memory and echoes it in the response body. - Extract sensitive data: Repeat requests to harvest different memory regions. Leaked data has been confirmed to include Base64-encoded session cookies, HTTP Authorization headers, and partial SAML assertions from prior requests.
- Session hijack or credential replay: Use extracted session tokens to authenticate to downstream services or replay stolen SAML assertions to impersonate users to the service provider.
PoC Request
GET /saml/login?wctx HTTP/1.1
Host: target-netscaler.example.com
User-Agent: Mozilla/5.0
Connection: close
# Response contains leaked memory after the HTML body.
# Look for Base64 blobs or Authorization header fragments.
IOCs
- High volume of
GET /saml/login?wctxrequests (without=) in NetScaler access logs - Unusual authentication events in SAML service provider logs (logins from unexpected IP ranges)
- Scanning activity probing
/cgi/GetAuthMethodsfrom the same source IPs
Remediation
# 1. Upgrade NetScaler ADC/Gateway:
# - 14.1 → 14.1-43.12 or later
# - 13.1 → 13.1-57.10 or later
# - 13.0 → Upgrade to 13.1 or 14.1 (EOL, no patch)
# 2. If immediate upgrade is not possible, disable SAML IDP functionality:
# In the Citrix ADC CLI:
set authentication samlIdPProfile -DISABLED
# 3. Apply a web application firewall (WAF) rule to block requests matching:
# URI: /saml/login Query: wctx without = sign
# Citrix ADC AppFW signature rule (add to your policy):
# RULE: MATCH_URI "/saml/login" AND QUERY_STRING "wctx" NOT CONTAINS "="
# ACTION: BLOCK
# 4. Review logs for prior exploitation:
grep 'GET /saml/login?wctx ' /var/nslog/httprequest.log | awk '{print $1}' | sort | uniq -c | sort -rn
← Back to the June 4 Security Roundup