---
id: CVE-2026-76145
title: >-
  An improper privilege management vulnerability in Genian SSL PNS allows an
  attacker to escalate to super administrator privileges and force the creation
  of an OS account by manipulating the permission column during CSV bulk user
  registra…
summary: >-
  An improper privilege management vulnerability in Genian SSL PNS allows an
  attacker to escalate to super administrator privileges and force the creation
  of an OS account by manipulating the permission column during CSV bulk user
  registra…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'
cwe:
  - CWE-269
vendor: 'Genians, Inc'
product: Genian SSL PNS (frodo-core)
affected:
  - genian_ssl_pns_frodo-core < 5.0.0
  - genian_ssl_pns_watchcat-ui < 5.0.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T05:17:09.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76145'
references:
  - url: >-
      https://github.com/genians/security-research/security/advisories/GHSA-8mjh-295r-5hf2
    label: vuln@krcert.or.kr
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T05:37:57.549Z'
---

## Overview

An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
