Back

CRITICAL

Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface

Published Oct 1, 2026

Description

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Affected products

Remediation

Vendor solution

Genian NAC 5.0.75 LTS Release: update to Revision 148667 or later.

Genian NAC 5.0.85 Release Stable: update to Revision 148666 or later.

Genian NAC 5.0.86 Release: update to Revision 148665 or later.

Genian ZTNA 6.0.35 LTS Release: update to Revision 148672 or later.

Genian ZTNA 6.0.45 Release Stable: update to Revision 148671 or later.

Genian ZTNA 6.0.46 Release: update to Revision 148670 or later.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner krcert
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a