CVE-2026-95102: Monta monta.app Missing Authentication for Critical Function
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any network-reachable attacker can exploit the affected WebSocket endpoints. No authentication, prior privileges, or user interaction are required.
What access could an attacker gain?
An attacker can impersonate charging stations, access sensitive data, and perform unauthorized actions. The issue can also enable privilege escalation and potentially compromise the broader system.
Are systems affected by default?
The available information states that the affected WebSocket endpoints lack proper authentication, but it does not specify configuration prerequisites or whether all deployments expose those endpoints by default.