CVE-2026-76143: Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass
Published Oct 1, 2026
·Updated
A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter.
Affected Software
1 affected component
Genians Genian SSL PNS
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Genian SSL PNS (frodo-core)to a version that resolves this vulnerability.Fixed in 5.0.0
Event History
Oct 1, 2026
CVE Published
via MITRE·04:53 AM
Data Sourced
via MITRE·04:53 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The vulnerability requires low privileges (PR:L). It is remotely reachable over the network and does not require user interaction.
2
What is the practical impact of a successful exploit?
An attacker can bypass multi-factor authentication by manipulating a login request parameter. The CVSS vector indicates high impact to confidentiality and to the confidentiality, integrity, and availability of subsequent systems.