A CISA alert published on October 1, 2026 says flaws in Monta monta.app could allow unauthorized administrative control of vulnerable charging stations or disruption of charging services. The alert lists all product versions as affected and names four identifiers: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474. Reported scores are 9.4 under CVSS 3.1 and 9.3 under CVSS 4.0, both critical.
The issues described include WebSocket endpoints without adequate authentication, no limit on authentication requests, insufficient session expiration, and inadequate credential protection. The alert cites possible access to sensitive data, unauthorized actions, brute-force attempts, and denial of service. It identifies energy and transportation as relevant sectors, says the product is deployed worldwide, and places the company headquarters in the Netherlands.
According to the alert, Monta is working to increase authenticated connections and phase out unauthenticated access. The company says it supports OCPP 1.6 Security Profile 2, using HTTP Basic Auth over TLS, and encourages operators to enable it. It also reports rate limiting and automated WebSocket connection controls to identify and block abusive patterns. Consult the team responsible for the stations and the vendor to assess measures for your environment; do not assume the alert confirms the current status of every installation.
To check the scope, identifiers, and updates, consult the original CISA advisory and its CSAF summary using the title and CVEs above. Compare those details with current product communications.