CVE-2026-93474: Monta monta.app Insufficiently Protected Credentials
Published Oct 2, 2026
·Updated
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Affected Software
1 affected component
Monta monta.app
Event History
Oct 2, 2026
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Organizations using Monta monta.app with charging station authentication identifiers that are exposed through web-based mapping platforms are affected.
2
What does an attacker need to exploit it?
The vector is network-accessible and requires no privileges or user interaction. An attacker would need access to the publicly available authentication identifiers on the relevant mapping platforms.
3
What is the likely impact?
The available scoring indicates low confidentiality and integrity impact, with no availability impact. The issue is rated medium severity with a CVSS score of 6.5.