
🔴 Monta EV charging platform hit by 4 critical WebSocket auth flaws Monta http://monta.app—deployed globally across energy and transportation sectors—contains four vulnerabilities (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) that enable attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service. WebSocket endpoints lack authentication, allowing attackers to impersonate stations and escalate privileges. Charging station identifiers are publicly accessible via web mapping platforms.
