CVE-2026-16520
Received Received - Intake

SQL Injection and Authentication Bypass in Genian NAC and ZTNA

Vulnerability report for CVE-2026-16520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: FSI

Description

Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. This issue affects Genian NAC V4.0: from 4.0.0 before 4.0.175(Revision 150340); Genian NAC V5.0: from 5.0.0 before 5.0.65 LTS(Revision 150331), from 5.0.0 before 5.0.75 LTS(Revision 150330), from 5.0.0 before 5.0.87 Release Stable(Revision 150329), and from 5.0.0 before 5.0.88(Revision 150328); Genian ZTNA V6.0: from 6.0.0 before 6.0.26 LTS(Revision 150337), from 6.0.0 before 6.0.35 LTS(Revision 150336), from 6.0.0 before 6.0.47 Release Stable(Revision 150334), and from 6.0.0 before 6.0.48(Revision 150333).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
genians genian_nac to 4.0.175 (exc)
genians genian_nac to 5.0.88 (exc)
genians genian_ztna to 6.0.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-202 When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation and exposure of sensitive information through data queries flaw in Genians Genian NAC and Genian ZTNA products. It allows SQL injection and authentication bypass, enabling unauthenticated attackers to manipulate URL parameters on the user search page to disclose administrator credentials from the user table without logging in.

Detection Guidance

To detect this vulnerability, check if your Genian NAC/ZTNA versions are below 4.0.175, 5.0.88, or 6.0.48. Review logs for unusual access to the user search page or unauthorized credential exposure. Inspect network traffic for SQL injection attempts or abnormal URL parameters targeting the CWP User Search feature.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to sensitive administrative credentials without any privileges or user interaction. This could lead to full system compromise, unauthorized data access, or control over the affected Genian NAC or ZTNA systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. It may result in data breaches, non-compliance with privacy regulations, and potential legal penalties due to exposure of protected health or personal information.

Mitigation Strategies

Immediately update Genian NAC/ZTNA to versions 4.0.175, 5.0.88, or 6.0.48 or later. If patching is not possible, apply temporary mitigations as outlined in Genian's advisory GN-SA-2026-003. Restrict access to the user search page and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart