CVE-2026-76142
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Summary
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Genians, Inc | Genian NAC 5.0.75 LTS Release | 135823 < 148667 | affected |
| Genians, Inc | Genian NAC 5.0.85 Release Stable | 147181 < 148666 | affected |
| Genians, Inc | Genian NAC 5.0.86 Release | 148018 < 148665 | affected |
| Genians, Inc | Genian ZTNA 6.0.35 LTS Release | 135814 < 148672 | affected |
| Genians, Inc | Genian ZTNA 6.0.45 Release Stable | 147169 < 148671 | affected |
| Genians, Inc | Genian ZTNA 6.0.46 Release | 148028 < 148670 | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
- CWE-306: CWE-306 Missing Authentication for Critical Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://docs.genians.com/release/ko/advisories/GN-SA-2026-002.html
- https://github.com/genians/security-research/security/advisories/GHSA-qf3p-2jpg-3h95
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.