CVE-2026-105030 PUBLISHED

Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor rajnandan1
Product kener
Versions Default: unaffected
  • affected from 4.0.0 to 4.1.6 (excl.)
  • Version 4.1.6 is unaffected

Credits

  • George Chen finder

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE