CVE-2026-76145 PUBLISHED

Genians, Inc Genian SSL PNS Improper Privilege Management

Assigner: krcert
Reserved: 19.08.2026 Published: 01.10.2026 Updated: 01.10.2026

An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 7.5

Product Status

Vendor Genians, Inc
Product Genian SSL PNS (frodo-core)
Versions Default: unaffected
  • affected from 0 to 5.0.0 (excl.)
Vendor Genians, Inc
Product Genian SSL PNS (watchcat-ui)
Versions Default: unaffected
  • affected from 0 to 5.0.0 (excl.)

Solutions

Update Genian SSL PNS frodo-core and watchcat-ui to version 5.0.0.

References

Problem Types

  • CWE-269 Improper Privilege Management CWE

Impacts

  • CAPEC-233