CVE-2026-76147

Summary

A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code

Affected Software

VendorProductVersion RangeStatus
Genians, IncGenian NAC 4.0.175 Release0 < 148817affected
Genians, IncGenian NAC 5.0.65 LTS Release0 < 148816affected
Genians, IncGenian NAC 5.0.75 LTS Release0 < 148815affected
Genians, IncGenian NAC 5.0.85 Release Stable0 < 148814affected
Genians, IncGenian NAC 5.0.86 Release0 < 148813affected
Genians, IncGenian ZTNA 6.0.26 LTS Release0 < 148811affected
Genians, IncGenian ZTNA 6.0.35 LTS Release0 < 148810affected
Genians, IncGenian ZTNA 6.0.45 Release Stable0 < 148809affected
Genians, IncGenian ZTNA 6.0.46 Release0 < 148807affected

Weaknesses

  • CWE-862: CWE-862
  • CWE-807: CWE-807
  • CWE-22: CWE-22

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References