Monta's EV Charging Platform Has No Patch for a 9.4 Authentication Gap
Security / news
Monta's EV Charging Platform Has No Patch for a 9.4 Authentication Gap
CISA lists four flaws in monta.app, all versions. The vendor points operators to an optional OCPP security profile and has shipped no fix.

An unauthenticated attacker on the network (no credentials, no user interaction) can impersonate a charging station to the monta.app platform, according to a CISA advisory published October 1, 2026. The flaw, CVE-2026-95102, scores 9.4 on CVSS v3.1. Monta has released no patch for any of the four flaws in ICSA-26-274-02, and the advisory covers all versions of the product.
Monta, headquartered in the Netherlands, runs EV charging management. CISA lists energy and transportation systems as the affected sectors and says exploitation "could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services."
The four CVEs and their preconditions
| CVE | Flaw | CVSS v3.1 | v4.0 |
|---|---|---|---|
| CVE-2026-95102 | Missing authentication on WebSocket endpoints | 9.4 | 9.3 |
| CVE-2026-97363 | No limit on authentication attempts | 7.5 | 8.7 |
| CVE-2026-97212 | Insufficient session expiration, predictable session identifiers | 7.3 | 6.9 |
| CVE-2026-93474 | Station authentication identifiers visible on web mapping platforms | 6.5 | 6.9 |
All four vectors are network-reachable, low-complexity and need no privileges. The 9.4 reflects high confidentiality and integrity impact with low availability impact.
The advisory does not connect the first and last entries, but they fit together. If a station's identifier is public on a map and the WebSocket endpoint does not check who is connecting, knowing the identifier may be all an impersonator needs. That is a reading of the advisory rather than a claim in it.
Monta's response: Security Profile 2, rate limiting, no patch
Per the advisory, Monta offers three responses. It supports "OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS)" and encourages operators to turn it on. It is implementing rate limiting and connection throttling at the WebSocket layer. And it handles duplicate connection attempts under the OCPP specification, where "a new authenticated connection supersedes an existing session."
CISA's status line is plain: no patch released, mitigations under development. It also says no known public exploitation targeting these vulnerabilities has been reported, and credits an anonymous researcher.
Why an opt-in security profile matters here
OCPP is the protocol chargers use to talk to a management system, maintained by the Open Charge Alliance. OCPP Lab's write-up on security profiles says the original OCPP 1.6 core specification "treated security as optional," and that the whitepaper adding security profiles was published years later and remains opt-in per deployment.

That makes Monta's mitigation a configuration choice for each deployment, not a platform fix. Operators running Profile 1, or no profile, stay exposed until they switch. The advisory does not say how many stations or operators use monta.app, or how many run a secured profile.
Monta is not alone in leaving CISA's October 1 batch unpatched. The advisory for the Meari IoT Cloud Platform OpenAPI Service, ICSA-26-274-06, lists CVE-2026-101104 (7.7) and CVE-2026-96613 (6.5), says no fix is planned, and says Meari did not respond to CISA's coordination attempts.
What operators can do now
CISA's general guidance applies: minimise network exposure, use firewalls, and keep remote access behind a VPN. For Monta, the specific step is enabling Security Profile 2 on every charger that supports it. Related coverage: Vermont's 110 MW home battery fleet and the Cisco SD-WAN Manager admin API bypass, where a missing authorization check was the whole bug.
The advisory gives no date for the promised rate limiting.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.