Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests. | |
| Title | Monta monta.app Insufficient Session Expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-02T21:30:37.104Z
Reserved: 2026-09-24T16:22:04.112Z
Link: CVE-2026-97212
No data.
Status : Received
Published: 2026-10-02T22:16:56.760
Modified: 2026-10-02T22:16:56.760
Link: CVE-2026-97212
No data.
OpenCVE Enrichment
No data.
-
CWE-613
Insufficient Session Expiration