---
id: CVE-2026-95102
title: >-
  WebSocket endpoints lack proper authentication mechanisms, enabling attackers
  to impersonate charging stations
summary: >-
  WebSocket endpoints lack proper authentication mechanisms, enabling attackers
  to impersonate charging stations. As a result, attackers can exploit this
  weakness to gain unauthorized access to sensitive data or perform unauthorized
  action…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-306
vendor: Monta
product: monta.app
affected:
  - monta.app All versions
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T22:16:56.607'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95102'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-02.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T22:33:09.852Z'
---

## Overview

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
