Session Identifier Vulnerability in Charging Station Systems by CISA
CVE-2026-97212
6.9MEDIUM
What is CVE-2026-97212?
The vulnerability arises due to the handling of session identifiers in the WebSocket backend of charging station systems. This design flaw allows multiple endpoints to connect while using the same session identifier, leading to predictable session identifiers. Consequently, unauthorized users may gain access to other users' sessions, jeopardizing sensitive information and user privacy. Additionally, this vulnerability may be exploited by attackers to launch a denial-of-service attack, overwhelming the backend with multiple valid session requests, which can disrupt service availability.
Affected Version(s)
monta.app All versions
