CVE-2026-76146: Genians, Inc Genian SSL PNS OS Command Injection
Published Oct 1, 2026
·Updated
An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely
Affected Software
1 affected component
Genians Genian SSL PNS
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Genian SSL PNS (xenics_auther)to a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Oct 1, 2026
CVE Published
via MITRE·04:53 AM
Data Sourced
via MITRE·04:53 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to know only a client access ID; the password is not required. No user interaction is required, and the vulnerability is remotely exploitable.
2
What could exploitation allow?
Successful exploitation allows remote execution of arbitrary operating-system commands. The supplied CVSS vector indicates high impact to confidentiality and availability and low impact to integrity.