Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Project Subscriptions

Vendors Products
Genians Subscribe
Genian Nac Subscribe
Genian Ztna Subscribe
Advisories

No advisories yet.

Fixes

Solution

Genian NAC 5.0.75 LTS Release: update to Revision 148667 or later. Genian NAC 5.0.85 Release Stable: update to Revision 148666 or later. Genian NAC 5.0.86 Release: update to Revision 148665 or later. Genian ZTNA 6.0.35 LTS Release: update to Revision 148672 or later. Genian ZTNA 6.0.45 Release Stable: update to Revision 148671 or later. Genian ZTNA 6.0.46 Release: update to Revision 148670 or later.


Workaround

No workaround given by the vendor.

History

Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Genians
Genians genian Nac
Genians genian Ztna
Vendors & Products Genians
Genians genian Nac
Genians genian Ztna

Thu, 01 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Title Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface
Weaknesses CWE-284
CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: krcert

Published:

Updated: 2026-10-01T15:58:20.134Z

Reserved: 2026-08-19T04:13:00.870Z

Link: CVE-2026-76142

cve-icon Vulnrichment

Updated: 2026-10-01T15:58:15.765Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T05:17:09.093

Modified: 2026-10-01T16:17:56.793

Link: CVE-2026-76142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:35:24Z

Weaknesses