Junglewise Threat Intelligence

CVE-2026-16520: Genians Genian NAC/ZTNA unauthenticated credential disclosure in user search

CVE-2026-16520 · Severity: info · CVSS 8.7 · Published 2026-08-21

Executive brief

Genian NAC and ZTNA are network access control and zero-trust network access solutions used to secure and monitor corporate network devices. An unauthenticated attacker can manipulate URL parameters on the user search page to extract administrator credentials without logging in, directly compromising administrative access to the entire security infrastructure.

Technical details

This vulnerability is an authentication bypass combined with sensitive data exposure via improper input validation in the CWP (Cloud Web Portal) user search functionality. The vulnerable component fails to enforce authentication checks before processing user search queries, allowing an unauthenticated attacker to craft malicious URL parameters to extract administrator credentials from the user table. The attack requires only network access to the affected system with no authentication, no special privileges, and no user interaction. An attacker can gain full administrative credentials, leading to complete compromise of the NAC/ZTNA deployment. Patches are available for all affected versions as detailed in the advisory.

Affected products

  • Genians Genian NAC V4.0 4.0.0 before 4.0.175 (Revision 150340)
  • Genians Genian NAC V5.0 5.0.0 before 5.0.65 LTS (Revision 150331), before 5.0.75 LTS (Revision 150330), before 5.0.87 Release Stable (Revision 150329), before 5.0.88 (Revision 150328)
  • Genians Genian ZTNA V6.0 6.0.0 before 6.0.26 LTS (Revision 150337), before 6.0.35 LTS (Revision 150336), before 6.0.47 Release Stable (Revision 150334), before 6.0.48 (Revision 150333)

Timeline

  • 2026-07-22: disclosed: Vulnerability publicly disclosed
  • 2026-07-09: patched: Patches released for all affected versions

References