CVE-2026-97363: Monta monta.app Improper Restriction of Excessive Authentication Attempts
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can target the WebSocket API remotely without prior privileges or user interaction. Exploitation consists of sending unrestricted authentication requests.
What are the practical impacts?
The lack of authentication rate limiting may enable denial-of-service attacks against the service. It may also permit brute-force authentication attempts that could result in unauthorized access if valid credentials are guessed.
How can I determine whether my deployment is exposed?
Determine whether your Monta monta.app deployment exposes or uses the affected WebSocket API for authentication. Then verify whether that API enforces limits on repeated authentication requests.