Insufficient Authentication Vulnerability in Genian NAC/ZTNA Policy Server
CVE-2026-76142

9.3CRITICAL

What is CVE-2026-76142?

An insufficient authentication and access control vulnerability exists within the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server. This flaw allows an unauthenticated attacker to interact with sensitive internal functions, potentially leading to unauthorized access and manipulation of the server's operations. Proper security measures must be implemented to safeguard against such threats and protect the integrity of the system.

Affected Version(s)

Genian NAC 5.0.75 LTS Release 135823 < 148667

Genian NAC 5.0.85 Release Stable 147181 < 148666

Genian NAC 5.0.86 Release 148018 < 148665

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

segyeong
.