CVE-2026-76142

Summary

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Affected Software

VendorProductVersion RangeStatus
Genians, IncGenian NAC 5.0.75 LTS Release135823 < 148667affected
Genians, IncGenian NAC 5.0.85 Release Stable147181 < 148666affected
Genians, IncGenian NAC 5.0.86 Release148018 < 148665affected
Genians, IncGenian ZTNA 6.0.35 LTS Release135814 < 148672affected
Genians, IncGenian ZTNA 6.0.45 Release Stable147169 < 148671affected
Genians, IncGenian ZTNA 6.0.46 Release148028 < 148670affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control
  • CWE-306: CWE-306 Missing Authentication for Critical Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References