cbcvebase.
CVE-2026-76142
published 2026-10-01

CVE-2026-76142: Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker…

PriorityP268critical9.3CVSS 4.0
AVNACLATNPRNUINVCLVIHVAHSCLSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.33%
24.4th percentile
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

Affected

6 ranges
VendorProductVersion rangeFixed in
genians_incgenian_nac_5.0.75_lts_release>= 135823 < 148667148667
genians_incgenian_nac_5.0.85_release_stable>= 147181 < 148666148666
genians_incgenian_nac_5.0.86_release>= 148018 < 148665148665
genians_incgenian_ztna_6.0.35_lts_release>= 135814 < 148672148672
genians_incgenian_ztna_6.0.45_release_stable>= 147169 < 148671148671
genians_incgenian_ztna_6.0.46_release>= 148028 < 148670148670
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.