CVE-2026-76142
Received Received - Intake

Unauthenticated Access in Genian NAC/ZTNA Policy Server

Vulnerability report for CVE-2026-76142, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: KrCERT/CC

Description

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
genians genian_nac 5.0
genians genian_nac 5.0
genians genian_ztna 6.0
genians genian_ztna 6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-76142 is a critical vulnerability in Genian NAC/ZTNA where insufficient authentication and access control on an internal-only IPC SOAP endpoint allows unauthenticated attackers to invoke internal functions. The issue occurs when the gnrpcsvc service (port 9999) is exposed to the internet via Apache ProxyPass, enabling calls to the internal endpoint (127.0.0.1:3870/ipc) on Centerd.

The flaw is classified under CWE-284 (Improper Access Control) and CWE-306 (Missing Authentication for Critical Function) and has a CVSS score of 9.3, indicating high severity.

Detection Guidance

Check if port 9999 is exposed to the internet by running a port scan like 'nmap -p 9999 <target_IP>'. Verify if the internal IPC SOAP endpoint (127.0.0.1:3870/ipc) is accessible from external networks.

Impact Analysis

An attacker could exploit this to gain unauthorized access to internal functions, potentially compromising system integrity and availability. This could lead to unauthorized changes, data breaches, or service disruptions in affected Genian NAC/ZTNA systems.

Mitigation Strategies

Immediately restrict access to port 9999 and the internal IPC endpoint. Apply the latest patches from Genians for affected versions. Temporarily disable the Apache ProxyPass configuration exposing gnrpcsvc if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76142. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart