type: cve · created: 2026-10-02 · updated: 2026-10-02 · tags: [cve, ics, energy, monta] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-97363 |
| CVSS | 8.7 (High) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| Vendor / product | Monta — monta.app EV charging management platform |
| Reported | 2026-10-02 |