CVE-2026-97212: Monta monta.app Insufficient Session Expiration
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using the Monta monta.app WebSocket backend are exposed where charging station identifiers are used to associate sessions. The issue affects sessions that can be reached through the backend and share the same identifier.
What does an attacker need to exploit it?
The reported vector is network-based and requires no privileges or user interaction. An attacker would need to use or predict a valid charging-station-based session identifier to create competing session connections.
What could exploitation allow?
An unauthorized user may be able to authenticate as another user. A malicious actor may also deny service by overwhelming the backend with valid session requests.