<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Authentication Bypass on Martin&#39;s Blog</title>
		<link>https://mac.sploit.dk/tags/authentication-bypass/</link>
		<description>Recent content in Authentication Bypass on Martin&#39;s Blog</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Fri, 11 Sep 2026 07:00:00 +0200</lastBuildDate>
		
			<atom:link href="https://mac.sploit.dk/tags/authentication-bypass/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>CVE-2026-19490: Assessing a Candidate NetScaler SAML Alternate Path</title>
				<link>https://mac.sploit.dk/blog/cve-2026-19490-netscaler-saml-logic-bug/</link>
				<pubDate>Fri, 11 Sep 2026 07:00:00 +0200</pubDate>
				<guid>https://mac.sploit.dk/blog/cve-2026-19490-netscaler-saml-logic-bug/</guid>
				<description>&lt;p&gt;CVE-2026-19490 is a vendor-confirmed authentication bypass in NetScaler ADC&#xA;and NetScaler Gateway. Citrix describes it as authentication&#xA;bypass through an alternate path, but its bulletin does not identify the&#xA;responsible binary or explain the failed security decision.&lt;/p&gt;&#xA;&lt;p&gt;Reverse engineering NetScaler 14.1 build 73.30 confirms a security-relevant&#xA;control-flow difference in the proprietary &lt;code&gt;nsppe&lt;/code&gt; packet engine. The SAML&#xA;HTTP-Redirect handler and a normal SAML response path call the same parser with&#xA;different mode values, and the Redirect value skips a later block of&#xA;signature-structure policy checks.&lt;/p&gt;&#xA;&lt;p&gt;That is real static evidence, but it is not enough to identify the CVE&amp;rsquo;s root&#xA;cause. In particular, the unsigned Redirect branch continues only for raw&#xA;policy value &lt;code&gt;2&lt;/code&gt;. Two local artifacts identify &lt;code&gt;2&lt;/code&gt; as deprecated permissive&#xA;&lt;code&gt;OFF&lt;/code&gt;, not default &lt;code&gt;ON&lt;/code&gt;. The two-function explanation is therefore a&#xA;candidate, disputed root cause rather than a validated default-policy bypass.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
