9.3

CVE-2026-76142

Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.75 LTS Release
Default Statusunaffected
Version 135823
Version < 148667
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.85 Release Stable
Default Statusunaffected
Version 147181
Version < 148666
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.86 Release
Default Statusunaffected
Version 148018
Version < 148665
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.35 LTS Release
Default Statusunaffected
Version 135814
Version < 148672
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.45 Release Stable
Default Statusunaffected
Version 147169
Version < 148671
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.46 Release
Default Statusunaffected
Version 148028
Version < 148670
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.242
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
krcert 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://docs.genians.com/release/ko/advisories/GN-SA-2026-002.html
https://github.com/genians/security-research/security/advisories/GHSA-qf3p-2jpg-3h95