CVE-2026-20518: Geniezone geniezone vulnerability
In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10867524 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10876355
Event History
Frequently Asked Questions
What level of access does an attacker need before this can be exploited?
The attacker must already have System privilege on the affected device. This is a local information-disclosure issue rather than an initial remote-access vector.
Is user interaction required?
Yes. Exploitation requires user interaction in addition to the attacker already having System privilege.
What patch identifiers should be used to track remediation?
The listed patch IDs are ALPS10867524 and ALPS10876355. The associated issue ID is MSV-6674.