{"id":"CVE-2026-76147","title":"A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code","summary":"A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code","severity":"medium","cvss":5.9,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22","CWE-807","CWE-862"],"vendor":"Genians, Inc","product":"Genian NAC 4.0.175 Release","affected":["genian_nac_4.0.175_release < 148817","genian_nac_5.0.65_lts_release < 148816","genian_nac_5.0.75_lts_release < 148815","genian_nac_5.0.85_release_stable < 148814","genian_nac_5.0.86_release < 148813","genian_ztna_6.0.26_lts_release < 148811","genian_ztna_6.0.35_lts_release < 148810","genian_ztna_6.0.45_release_stable < 148809","genian_ztna_6.0.46_release < 148807"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T05:17:09.933","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76147","references":[{"url":"https://docs.genians.com/release/ko/advisories/GN-SA-2026-001.html","label":"vuln@krcert.or.kr"},{"url":"https://github.com/genians/security-research/security/advisories/GHSA-c883-w46g-6mg5","label":"vuln@krcert.or.kr"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-01T05:37:57.550Z","slug":"CVE-2026-76147","body":"## Overview\n\nA path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}