Junglewise Threat Intelligence

CVE-2026-97212: Monta monta.app authentication and session management vulnerabilities

CVE-2026-97212 · Severity: high · Published 2026-10-01

Executive brief

Monta monta.app is a software platform for managing electric vehicle charging stations used in critical energy infrastructure worldwide. Multiple authentication and credential-handling vulnerabilities could allow attackers to gain unauthorized administrative control over charging stations or disrupt charging services through brute-force attacks and session hijacking.

Technical details

The application contains missing authentication for critical functions, weak rate limiting on authentication attempts, insufficient session expiration, and insufficiently protected credential storage. These issues allow attackers with network access to bypass authentication controls, perform credential brute-forcing, maintain unauthorized sessions, and extract stored credentials. No patch information is currently available.

Affected products

  • Monta monta.app all

CVE identifiers

  • CVE-2026-97212
  • CVE-2026-93474
  • CVE-2026-97363
  • CVE-2026-95102

Timeline

  • 2026-10-01: disclosed