---
id: CVE-2026-76147
title: >-
  A path traversal (ZIP Slip) vulnerability caused by insufficient authorization
  and integrity verification in the agent upgrade feature of Genian NAC/ZTNA
  allows a remote attacker to execute arbitrary code
summary: >-
  A path traversal (ZIP Slip) vulnerability caused by insufficient authorization
  and integrity verification in the agent upgrade feature of Genian NAC/ZTNA
  allows a remote attacker to execute arbitrary code
severity: medium
cvss: 5.9
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
  - CWE-807
  - CWE-862
vendor: 'Genians, Inc'
product: Genian NAC 4.0.175 Release
affected:
  - genian_nac_4.0.175_release < 148817
  - genian_nac_5.0.65_lts_release < 148816
  - genian_nac_5.0.75_lts_release < 148815
  - genian_nac_5.0.85_release_stable < 148814
  - genian_nac_5.0.86_release < 148813
  - genian_ztna_6.0.26_lts_release < 148811
  - genian_ztna_6.0.35_lts_release < 148810
  - genian_ztna_6.0.45_release_stable < 148809
  - genian_ztna_6.0.46_release < 148807
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T05:17:09.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76147'
references:
  - url: 'https://docs.genians.com/release/ko/advisories/GN-SA-2026-001.html'
    label: vuln@krcert.or.kr
  - url: >-
      https://github.com/genians/security-research/security/advisories/GHSA-c883-w46g-6mg5
    label: vuln@krcert.or.kr
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T05:37:57.550Z'
---

## Overview

A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
