type: cve · created: 2026-10-02 · updated: 2026-10-02 · tags: [cve, ics, energy, monta] · confidence: medium · severity: medium · affected_sectors: [global] · au_impact: false
Charging-station authentication identifiers for the Monta monta.app electric-vehicle charging management platform are publicly accessible via web-based mapping platforms — exposing the identifiers an attacker needs to address individual charging stations. CISA published the flaw on 1 October 2026 in ICS advisory ICSA-26-274-02 as one of four vulnerabilities in the platform, all affecting all versions and all reported by an anonymous researcher; the advisory states no known public exploitation had been reported to CISA at the time of publication.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-93474 |
| CVSS | 6.9 (Medium) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| Vendor / product | Monta — monta.app EV charging management platform |
| Reported | 2026-10-02 |