Critical Authentication Bypass Vulnerabilities (CVE‑2026‑95102, CVE‑2026‑97363, CVE‑2026‑97212, CVE‑2026‑93474) in Monta monta.app Threaten EV Charging Infrastructure
What It Is – The U.S. Cybersecurity & Infrastructure Security Agency (CISA) issued an advisory identifying four high‑severity flaws in Monta’s cloud‑based charging‑station management platform monta.app. The vulnerabilities include missing authentication on WebSocket endpoints, weak session handling, and insufficient credential protection, each assigned a CVSS v3.1 score of 9.4.
Exploitability – Publicly disclosed CVEs indicate that exploitation requires only network access to the SaaS API; no proof‑of‑concept code is required for an attacker to impersonate a charging station or obtain administrative privileges.
Affected Products – Monta monta.app (all released versions).
Why It Matters for Trust & Control Assurance
- Identity & Access Controls – Missing authentication directly violates the control objective of enforcing least‑privilege access and strong identity verification for critical functions.
- Continuous Monitoring – The flaws highlight the need for real‑time audit logs and anomaly detection to prove that only authorized entities are interacting with charging‑station APIs.
- Defensible Audit Trail – Demonstrating remediation (patches, MFA, session‑timeout policies) provides evidence for regulators and enterprise buyers that the SaaS provider meets rigorous control‑assurance expectations.
Recommended Actions
- Apply Monta’s latest security patches immediately.
- Enforce multi‑factor authentication and strict API‑gateway policies for all service‑to‑service calls.
- Implement session‑expiration limits and rotate credentials on a regular schedule.
- Enable continuous logging of admin actions and integrate alerts into a SIEM for rapid detection.
- Document the remediation steps in your control‑evidence repository to support audit readiness.
Source: CISA Advisory – ICSA‑26‑274‑02