CVE-2026-97212
published 2026-10-02CVE-2026-97212: The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session…
PriorityP342high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.25%
14.8th percentile
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| monta | monta.app | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier.
ghsa_unreviewed·2026-10-03
CVE-2026-97212 [MEDIUM] CWE-613 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier.
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
VulDB
Monta monta.app WebSocket backend improper authorization
vuldb·2026-10-03·CVSS 7.3
CVE-2026-97212 [HIGH] Monta monta.app WebSocket backend improper authorization
A vulnerability labeled as critical has been found in Monta monta.app. This affects an unknown function of the component WebSocket backend. Such manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-97212. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-02
Published