CVE-2026-95102: Monta monta.app Missing Authentication for Critical Function

Published Oct 2, 2026
·
Updated

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

Affected Software

1 affected component
Monta monta.app

Event History

Oct 2, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any network-reachable attacker can exploit the affected WebSocket endpoints. No authentication, prior privileges, or user interaction are required.

2

What access could an attacker gain?

An attacker can impersonate charging stations, access sensitive data, and perform unauthorized actions. The issue can also enable privilege escalation and potentially compromise the broader system.

3

Are systems affected by default?

The available information states that the affected WebSocket endpoints lack proper authentication, but it does not specify configuration prerequisites or whether all deployments expose those endpoints by default.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203