OS Command Injection Vulnerability in Genian SSL PNS Product
CVE-2026-76146

8.4HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-76146?

An OS command injection vulnerability in the Genian SSL PNS product enables attackers to execute arbitrary commands remotely simply by possessing the client access ID. This security flaw does not require the attacker to have the password, thus compromising the system's integrity and confidentiality. It is crucial for organizations using the affected product to implement patches and follow security best practices to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Genian SSL PNS (xenics_auther) 0 < 1.0.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.