CVE-2026-76142: Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Genian NAC 5.0.75 LTSto a version that resolves this vulnerability.Patch Revision 148667 - Upgrade
Upgrade
Genian NAC 5.0.85 Stableto a version that resolves this vulnerability.Patch Revision 148666 - Upgrade
Upgrade
Genian NAC 5.0.86to a version that resolves this vulnerability.Patch Revision 148665 - Upgrade
Upgrade
Genian ZTNA 6.0.35 LTSto a version that resolves this vulnerability.Patch Revision 148672 - Upgrade
Upgrade
Genian ZTNA 6.0.45 Stableto a version that resolves this vulnerability.Patch Revision 148671 - Upgrade
Upgrade
Genian ZTNA 6.0.46to a version that resolves this vulnerability.Patch Revision 148670
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
No authentication, privileges, or user interaction are required. The vulnerability can be exploited over the network by invoking functions exposed through the internal IPC SOAP endpoint.
Which deployments are exposed?
Deployments are exposed where an attacker can reach the policy server's internal-only IPC SOAP endpoint. The provided information does not identify affected versions or state whether the endpoint is reachable in a default deployment.
What is the potential impact of successful exploitation?
An unauthenticated attacker can invoke internal functions on the Genian NAC/ZTNA policy server. The supplied CVSS vector indicates high impact to integrity and availability, with low impact to confidentiality, including impacts on subsequent systems.