---
id: CVE-2026-105030
title: >-
  Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that
  allows unauthenticated attackers to retrieve hidden or inactive monitor data
  by querying dashboard API handlers lacking visibility filters
summary: >-
  Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that
  allows unauthenticated attackers to retrieve hidden or inactive monitor data
  by querying dashboard API handlers lacking visibility filters. Attackers can
  supp…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: rajnandan1
product: kener
affected:
  - kener >= 4.0.0 < 4.1.6
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T00:16:36.743'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105030'
references:
  - url: 'https://github.com/rajnandan1/kener'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rajnandan1/kener/commit/e8ce31898bf73ffe6be07c9b299da2a7330ddba5
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rajnandan1/kener/issues/848'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kener-4.0.0-before-4.1.6-hidden-monitor-data-disclosure-via-dashboard-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T23:34:57.407Z'
---

## Overview

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
