Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. | |
| Title | Monta monta.app Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-02T21:34:37.182Z
Reserved: 2026-09-24T16:22:04.106Z
Link: CVE-2026-95102
No data.
Status : Received
Published: 2026-10-02T22:16:56.607
Modified: 2026-10-02T22:16:56.607
Link: CVE-2026-95102
No data.
OpenCVE Enrichment
Updated: 2026-10-02T22:30:19Z