Search
Find a vulnerability
Search criteria
2 vulnerabilities found for Genian ZTNA 6.0.46 Release by Genians, Inc
CVE-2026-76147 (GCVE-0-2026-76147)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:53 – Updated: 2026-10-01 15:49
VLAI
EPSS
VEX
Title
Genians, Inc Genian NAC/ZTNA Remote Code Execution
Summary
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:49 UTC
Assigner
References
Impacted products
9 products
| Vendor | Product | Version | |
|---|---|---|---|
| Genians, Inc | Genian NAC 4.0.175 Release |
Affected:
0 , < 148817
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.65 LTS Release |
Affected:
0 , < 148816
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.75 LTS Release |
Affected:
0 , < 148815
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.85 Release Stable |
Affected:
0 , < 148814
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.86 Release |
Affected:
0 , < 148813
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.26 LTS Release |
Affected:
0 , < 148811
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.35 LTS Release |
Affected:
0 , < 148810
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.45 Release Stable |
Affected:
0 , < 148809
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.46 Release |
Affected:
0 , < 148807
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76147",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:49:04.514570Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:49:14.311Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Genian NAC 4.0.175 Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148817",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.65 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148816",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.75 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148815",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.85 Release Stable",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148814",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.86 Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148813",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.26 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148811",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.35 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148810",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.45 Release Stable",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148809",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.46 Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148807",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "segyeong"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code\u003c/p\u003e"
}
],
"value": "A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-807",
"description": "CWE-807",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:53:39.899Z",
"orgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
"shortName": "krcert"
},
"references": [
{
"url": "https://docs.genians.com/release/ko/advisories/GN-SA-2026-001.html"
},
{
"url": "https://github.com/genians/security-research/security/advisories/GHSA-c883-w46g-6mg5"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eGenian NAC 4.0.175 Release: update to Revision 148817 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.65 LTS Release: update to Revision 148816 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.75 LTS Release: update to Revision 148815 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.85 Release Stable: update to Revision 148814 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.86 Release: update to Revision 148813 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.26 LTS Release: update to Revision 148811 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.35 LTS Release: update to Revision 148810 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.45 Release Stable: update to Revision 148809 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.46 Release: update to Revision 148807 or later.\u003c/p\u003e"
}
],
"value": "Genian NAC 4.0.175 Release: update to Revision 148817 or later.\n\n\n\nGenian NAC 5.0.65 LTS Release: update to Revision 148816 or later.\n\n\n\nGenian NAC 5.0.75 LTS Release: update to Revision 148815 or later.\n\n\n\nGenian NAC 5.0.85 Release Stable: update to Revision 148814 or later.\n\n\n\nGenian NAC 5.0.86 Release: update to Revision 148813 or later.\n\n\n\nGenian ZTNA 6.0.26 LTS Release: update to Revision 148811 or later.\n\n\n\nGenian ZTNA 6.0.35 LTS Release: update to Revision 148810 or later.\n\n\n\nGenian ZTNA 6.0.45 Release Stable: update to Revision 148809 or later.\n\n\n\nGenian ZTNA 6.0.46 Release: update to Revision 148807 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Genians, Inc Genian NAC/ZTNA Remote Code Execution",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
"assignerShortName": "krcert",
"cveId": "CVE-2026-76147",
"datePublished": "2026-10-01T04:53:39.899Z",
"dateReserved": "2026-08-19T04:13:28.895Z",
"dateUpdated": "2026-10-01T15:49:14.311Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76142 (GCVE-0-2026-76142)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:53 – Updated: 2026-10-01 15:58
VLAI
EPSS
VEX
Title
Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface
Summary
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:58 UTC
Assigner
References
Impacted products
6 products
| Vendor | Product | Version | |
|---|---|---|---|
| Genians, Inc | Genian NAC 5.0.75 LTS Release |
Affected:
135823 , < 148667
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.85 Release Stable |
Affected:
147181 , < 148666
(custom)
|
|
| Genians, Inc | Genian NAC 5.0.86 Release |
Affected:
148018 , < 148665
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.35 LTS Release |
Affected:
135814 , < 148672
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.45 Release Stable |
Affected:
147169 , < 148671
(custom)
|
|
| Genians, Inc | Genian ZTNA 6.0.46 Release |
Affected:
148028 , < 148670
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76142",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:58:10.619392Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:58:20.134Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.75 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148667",
"status": "affected",
"version": "135823",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.85 Release Stable",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148666",
"status": "affected",
"version": "147181",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian NAC 5.0.86 Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148665",
"status": "affected",
"version": "148018",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.35 LTS Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148672",
"status": "affected",
"version": "135814",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.45 Release Stable",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148671",
"status": "affected",
"version": "147169",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Genian ZTNA 6.0.46 Release",
"vendor": "Genians, Inc",
"versions": [
{
"lessThan": "148670",
"status": "affected",
"version": "148028",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "segyeong"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eInsufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions\u003c/p\u003e"
}
],
"value": "Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions"
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:53:35.730Z",
"orgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
"shortName": "krcert"
},
"references": [
{
"url": "https://docs.genians.com/release/ko/advisories/GN-SA-2026-002.html"
},
{
"url": "https://github.com/genians/security-research/security/advisories/GHSA-qf3p-2jpg-3h95"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eGenian NAC 5.0.75 LTS Release: update to Revision 148667 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.85 Release Stable: update to Revision 148666 or later.\u003c/p\u003e\u003cp\u003eGenian NAC 5.0.86 Release: update to Revision 148665 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.35 LTS Release: update to Revision 148672 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.45 Release Stable: update to Revision 148671 or later.\u003c/p\u003e\u003cp\u003eGenian ZTNA 6.0.46 Release: update to Revision 148670 or later.\u003c/p\u003e"
}
],
"value": "Genian NAC 5.0.75 LTS Release: update to Revision 148667 or later.\n\n\n\nGenian NAC 5.0.85 Release Stable: update to Revision 148666 or later.\n\n\n\nGenian NAC 5.0.86 Release: update to Revision 148665 or later.\n\n\n\nGenian ZTNA 6.0.35 LTS Release: update to Revision 148672 or later.\n\n\n\nGenian ZTNA 6.0.45 Release Stable: update to Revision 148671 or later.\n\n\n\nGenian ZTNA 6.0.46 Release: update to Revision 148670 or later."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "cdd7a122-0fae-4202-8d86-14efbacc2863",
"assignerShortName": "krcert",
"cveId": "CVE-2026-76142",
"datePublished": "2026-10-01T04:53:35.730Z",
"dateReserved": "2026-08-19T04:13:00.870Z",
"dateUpdated": "2026-10-01T15:58:20.134Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}