OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-76142

CRITICAL · CVSS 9.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Genian NAC/ZTNA policy server has a critical vulnerability due to insufficient authentication and access control on its internal IPC SOAP endpoint, enabling unauthenticated attackers to invoke sensitive internal functions. This flaw poses a significant risk of unauthorized access and potential exploitation of the system. Organizations using Genian NAC/ZTNA should prioritize immediate remediation to mitigate the risk of compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76142
Severity
CRITICAL
CVSS
9.3
EPSS
0.33%

Original NVD Description

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions