CVE-2026-76142 PUBLISHED

Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface

Assigner: krcert
Reserved: 19.08.2026 Published: 01.10.2026 Updated: 01.10.2026

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Genians, Inc
Product Genian NAC 5.0.75 LTS Release
Versions Default: unaffected
  • affected from 135823 to 148667 (excl.)
Vendor Genians, Inc
Product Genian NAC 5.0.85 Release Stable
Versions Default: unaffected
  • affected from 147181 to 148666 (excl.)
Vendor Genians, Inc
Product Genian NAC 5.0.86 Release
Versions Default: unaffected
  • affected from 148018 to 148665 (excl.)
Vendor Genians, Inc
Product Genian ZTNA 6.0.35 LTS Release
Versions Default: unaffected
  • affected from 135814 to 148672 (excl.)
Vendor Genians, Inc
Product Genian ZTNA 6.0.45 Release Stable
Versions Default: unaffected
  • affected from 147169 to 148671 (excl.)
Vendor Genians, Inc
Product Genian ZTNA 6.0.46 Release
Versions Default: unaffected
  • affected from 148028 to 148670 (excl.)

Solutions

Genian NAC 5.0.75 LTS Release: update to Revision 148667 or later.

Genian NAC 5.0.85 Release Stable: update to Revision 148666 or later.

Genian NAC 5.0.86 Release: update to Revision 148665 or later.

Genian ZTNA 6.0.35 LTS Release: update to Revision 148672 or later.

Genian ZTNA 6.0.45 Release Stable: update to Revision 148671 or later.

Genian ZTNA 6.0.46 Release: update to Revision 148670 or later.

Credits

  • segyeong finder

References

Problem Types

  • CWE-284 Improper Access Control CWE
  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-115