Cisagov Csaf: Four Vulnerabilities Including Critical Auth Bypass Disclosed Together
Key findings • Four vulnerabilities in Cisagov's Csaf (monta.app) disclosed on October 2, 2026, range from Medium to Critical severity. • Critical CVE-2026-95102 allows attackers to impersona…

Key findings
- Four vulnerabilities in Cisagov's Csaf (monta.app) disclosed on October 2, 2026, range from Medium to Critical severity.
- Critical CVE-2026-95102 allows attackers to impersonate charging stations due to missing authentication in WebSocket endpoints.
- High severity CVE-2026-97363 and CVE-2026-97212 involve insufficient rate limiting and predictable session identifiers, respectively.
- Medium severity CVE-2026-93474 exposes charging station authentication identifiers publicly.
- All versions of monta.app are affected; users should monitor CISA for updates.
On October 2, 2026, CISA released an advisory detailing four vulnerabilities in Cisagov's Csaf product, specifically affecting the monta.app platform. These vulnerabilities, disclosed on the same day, range in severity from Medium to Critical, with three of them posing significant risks to the integrity and availability of charging station services. The most severe, CVE-2026-95102, is a Critical-severity flaw that allows attackers to impersonate charging stations due to a lack of proper authentication mechanisms in WebSocket endpoints. This could lead to unauthorized access to sensitive data or actions, including privilege escalation.
The batch of vulnerabilities highlights several weaknesses in the WebSocket implementation of the Csaf product. CVE-2026-97363, a High-severity vulnerability, points to a lack of restrictions on the number of authentication requests, potentially enabling denial-of-service or brute-force attacks. Another High-severity issue, CVE-2026-97212, arises from the use of predictable session identifiers, where multiple endpoints can connect with the same identifier, potentially allowing unauthorized users to authenticate as others. Finally, CVE-2026-93474, a Medium-severity vulnerability, reveals that charging station authentication identifiers are publicly accessible through web-based mapping platforms.
Successful exploitation of these vulnerabilities could allow attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services. CISA's advisory explicitly states that these exploits could lead to denial-of-service attacks. The vulnerabilities affect all versions of monta.app.
Cisagov has not yet released specific patches for these vulnerabilities, but the CISA advisory indicates that the affected product is monta.app, version all/*. Users are advised to monitor CISA for any updates or patches related to these issues.
The coordinated disclosure of these four vulnerabilities underscores the importance of robust authentication and authorization mechanisms in connected systems, particularly in critical infrastructure sectors like energy and transportation. Users of Cisagov's Csaf product, specifically the monta.app platform, should be aware of these risks and prepare to apply any available security updates as soon as they are released to mitigate potential impacts.