Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. | |
| Title | Monta monta.app Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-03T15:52:54.557Z
Reserved: 2026-09-24T16:22:04.106Z
Link: CVE-2026-95102
Updated: 2026-10-03T15:51:47.079Z
Status : Received
Published: 2026-10-02T22:16:56.607
Modified: 2026-10-03T16:16:46.090
Link: CVE-2026-95102
No data.
OpenCVE Enrichment
Updated: 2026-10-02T22:30:19Z
-
CWE-306
Missing Authentication for Critical Function