PT-2026-103682 · Genians · Genian Nac 4.0.175 Release+8

·

CVE-2026-76147

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v4.0

5.9

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code

Fix

Path traversal

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76147

Affected Products

Genian Nac 4.0.175 Release
Genian Nac 5.0.65 Lts Release
Genian Nac 5.0.75 Lts Release
Genian Nac 5.0.85 Release Stable
Genian Nac 5.0.86 Release
Genian Ztna 6.0.26 Lts Release
Genian Ztna 6.0.35 Lts Release
Genian Ztna 6.0.45 Release Stable
Genian Ztna 6.0.46 Release