VYPR

security-research

by Genians

CVEs (4)

  • CVE-2026-76142CriOct 1, 2026
    risk 0.60cvss —epss —

    Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

  • CVE-2026-16520HigAug 21, 2026
    risk 0.57cvss —epss 0.01

    Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. This issue affects Genian NAC V4.0: from 4.0.0…

  • CVE-2026-76145HigOct 1, 2026
    risk 0.49cvss —epss —

    An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration

  • CVE-2026-76147MedOct 1, 2026
    risk 0.38cvss —epss —

    A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code