Information Disclosure Vulnerability in Kener Products by Kener Inc.
CVE-2026-105030

6.9MEDIUM

Key Information:

Vendor

Rajnandan1

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-105030?

Kener versions prior to 4.1.6 present an information disclosure vulnerability that allows attackers without authentication to access sensitive monitor data through the dashboard's API. By exploiting endpoints that lack proper visibility filters, such as monitor-bar and monitor-latency-chart, attackers can provide known or guessed monitor tags to retrieve detailed information, including names, descriptions, statuses, uptime history, and latency metrics. This security flaw highlights the importance of implementing visibility controls in API endpoints to protect sensitive data from unauthorized access.

Affected Version(s)

kener 4.0.0 < 4.1.6

kener 4.1.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.