CVE-2026-105030
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rajnandan1 | kener | 4.0.0 < 4.1.6 | affected |
| rajnandan1 | kener | 4.1.6 | unaffected |
Weaknesses
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
References
- https://github.com/rajnandan1/kener/issues/848
- https://github.com/rajnandan1/kener/commit/e8ce31898bf73ffe6be07c9b299da2a7330ddba5
- https://github.com/rajnandan1/kener
- https://www.vulncheck.com/advisories/kener-4.0.0-before-4.1.6-hidden-monitor-data-disclosure-via-dashboard-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.