Session Identifier Vulnerability in Charging Station Systems by CISA
CVE-2026-97212

6.9MEDIUM

Key Information:

Vendor

Monta

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-97212?

The vulnerability arises due to the handling of session identifiers in the WebSocket backend of charging station systems. This design flaw allows multiple endpoints to connect while using the same session identifier, leading to predictable session identifiers. Consequently, unauthorized users may gain access to other users' sessions, jeopardizing sensitive information and user privacy. Additionally, this vulnerability may be exploited by attackers to launch a denial-of-service attack, overwhelming the backend with multiple valid session requests, which can disrupt service availability.

Affected Version(s)

monta.app All versions

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.