5.9

CVE-2026-76147

Genians, Inc Genian NAC/ZTNA Remote Code Execution

A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGenians, Inc
≫
Produkt Genian NAC 4.0.175 Release
Default Statusunaffected
Version 0
Version < 148817
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.65 LTS Release
Default Statusunaffected
Version 0
Version < 148816
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.75 LTS Release
Default Statusunaffected
Version 0
Version < 148815
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.85 Release Stable
Default Statusunaffected
Version 0
Version < 148814
Status affected
HerstellerGenians, Inc
≫
Produkt Genian NAC 5.0.86 Release
Default Statusunaffected
Version 0
Version < 148813
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.26 LTS Release
Default Statusunaffected
Version 0
Version < 148811
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.35 LTS Release
Default Statusunaffected
Version 0
Version < 148810
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.45 Release Stable
Default Statusunaffected
Version 0
Version < 148809
Status affected
HerstellerGenians, Inc
≫
Produkt Genian ZTNA 6.0.46 Release
Default Statusunaffected
Version 0
Version < 148807
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.322
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
krcert 5.9 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CWE-807 Reliance on Untrusted Inputs in a Security Decision

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://docs.genians.com/release/ko/advisories/GN-SA-2026-001.html
https://github.com/genians/security-research/security/advisories/GHSA-c883-w46g-6mg5