Information Disclosure Vulnerability in Kener Products by Kener Inc.
CVE-2026-105030
6.9MEDIUM
What is CVE-2026-105030?
Kener versions prior to 4.1.6 present an information disclosure vulnerability that allows attackers without authentication to access sensitive monitor data through the dashboard's API. By exploiting endpoints that lack proper visibility filters, such as monitor-bar and monitor-latency-chart, attackers can provide known or guessed monitor tags to retrieve detailed information, including names, descriptions, statuses, uptime history, and latency metrics. This security flaw highlights the importance of implementing visibility controls in API endpoints to protect sensitive data from unauthorized access.
Affected Version(s)
kener 4.0.0 < 4.1.6
kener 4.1.6
