CVE-2026-93474

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-01: 310-01
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • NewsTongue@NewsTongueX

    🔴 Monta EV charging platform hit by 4 critical WebSocket auth flaws Monta http://monta.app—deployed globally across energy and transportation sectors—contains four vulnerabilities (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) that enable attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service. WebSocket endpoints lack authentication, allowing attackers to impersonate stations and escalate privileges. Charging station identifiers are publicly accessible via web mapping platforms.

    0000029
    951 followersView on X
  • NewsTongue@NewsTongueX

    🔴 Monta EV charging platform hit by 4 critical WebSocket auth flaws Monta http://monta.app—deployed globally across energy and transportation sectors—contains four vulnerabilities (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) that enable attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service. WebSocket endpoints lack authentication, allowing attackers to impersonate stations and escalate privileges. Charging station identifiers are publicly accessible via web mapping platforms.

    0000029
    951 followersView on X
  • NewsTongue@NewsTongueX

    🔴 Monta EV charging platform hit by 4 critical WebSocket auth flaws Monta http://monta.app—deployed globally across energy and transportation sectors—contains four vulnerabilities (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) that enable attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service. WebSocket endpoints lack authentication, allowing attackers to impersonate stations and escalate privileges. Charging station identifiers are publicly accessible via web mapping platforms.

    0000038
    951 followersView on X

Explore more