CVE-2026-10816
Analyzed
Analyzed - Analysis Complete
Unauthenticated Arbitrary File Read in NetScaler ADC and Gateway
Vulnerability report for CVE-2026-10816, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-30
Last updated on: 2026-07-02
Assigner: 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
Description
Description
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| citrix | netscaler_application_delivery_controller | From 13.1 (inc) to 13.1-63.18 (exc) |
| citrix | netscaler_application_delivery_controller | From 14.1 (inc) to 14.1-72.61 (exc) |
| citrix | netscaler_application_delivery_controller | to 13.1-37.272 (exc) |
| citrix | netscaler_application_delivery_controller | to 13.1-37.272 (exc) |
| citrix | netscaler_application_delivery_controller | 14.1-66.68 |
| citrix | netscaler_gateway | From 13.1 (inc) to 13.1-63.18 (exc) |
| citrix | netscaler_gateway | From 14.1 (inc) to 14.1-72.61 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-610 | The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere. |
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |