Citrix NetScaler ADC and Gateway ns_monuploadd_err.pl Remote OS Command Injection Exploit

This module exploits CVE-2026-88771, a command injection vulnerability present in the ns_monuploadd_err.pl script of Citrix NetScaler ADC and Gateway to deploy a Core Impact Network agent that will run with root privileges. The module will exploit the vulnerability by sending a crafted HTTP POST request the /p/u/doAuthentication.do endpoint with the payload inside the User-Agent header. The result of the HTTP request will determine if the command injection was successful. If the command injection is successful, the module will wait up to 24 hours for agent connection. This is because the appliance runs the ns_monuploadd_err.pl script every 24 hours and the attack has no way to determine the current timelapse for this behaviour. The deployed Core Impact Network agent will run with root privileges.
Exploit Platform
Product Name