Overview
Monta, a Netherlands-based EV charging management platform (monta.app), is affected by a critical missing-authentication vulnerability tracked as CVE-2026-95102. The flaw carries a CVSS 3.1 score of 9.4 (Critical) and was published by NVD on October 2, 2026, alongside a companion CISA ICS advisory (ICSA-26-274-02) released October 1, 2026 that bundles four related Monta vulnerabilities.
Monta's backend communicates with physical EV chargers over OCPP (Open Charge Point Protocol), the industry-standard protocol for charge-point-to-management-system communication, carried over a WebSocket connection. According to the NVD description, Monta's WebSocket endpoints "lack proper authentication mechanisms, enabling attackers to impersonate charging stations." Independent reporting adds the specific mechanism: a charger opens a WebSocket to the backend and identifies itself only with its station ID — and because authentication is not enforced, that ID is effectively the only "secret" involved. A related CVE in the same advisory bundle (CVE-2026-93474) documents that station IDs are publicly discoverable via public charging-map platforms, which removes even that weak barrier.
This squarely lands in OT/ICS territory: EV charging infrastructure sits at the intersection of consumer-facing software and physical energy-delivery hardware, and CISA's classification of the Monta platform under Energy and Transportation Systems critical-infrastructure sectors reflects that. Unlike a typical web-app authentication bug, exploitation here can translate into unauthorized control over physical charging hardware, not just data exposure.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-95102 |
| Severity | Critical |
| CVSS v3.1 Score | 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L) |
| CVSS v4.0 Score | 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N) |
| CWE | CWE-306 (Missing Authentication for Critical Function) |
| Vendor / Product | Monta (Netherlands) / monta.app EV charging management platform |
| Vulnerable Component | OCPP WebSocket endpoint used for charger-to-backend communication |
| Vulnerable Identifier | Charging station ID — used as the sole connection identifier, with no accompanying credential |
| Affected Versions | All versions (platform-wide; no version-specific scope given by the vendor or NVD) |
| Fixed Version | None published as a version number — Monta's documented mitigation is enabling OCPP 1.6 Security Profile 2 (HTTP Basic Auth over TLS) per station, see Recommendations |
| Attack Vector | Network, low attack complexity, no privileges required, no user interaction |
| Related CVEs (same CISA bundle) | CVE-2026-97363 (no auth rate limiting, CWE-307, CVSS 7.5), CVE-2026-97212 (session ID reuse/insufficient expiration, CWE-613, CVSS 7.3), CVE-2026-93474 (station IDs exposed via public charging maps, CWE-522, CVSS 6.5) |
| Exploit Status | No public proof-of-concept found; not listed in CISA's KEV catalog as of October 3, 2026; EPSS ≈ 0.34% (≈25.3rd percentile) |
| Advisory | CISA ICSA-26-274-02 (October 1, 2026) |
| Source | NVD / CISA ICS-CERT |
How It Works
What the OCPP WebSocket endpoint does
OCPP is the de facto standard protocol for communication between a physical charge point (the charger hardware) and a backend Charging Station Management System (CSMS) — in this case, Monta's cloud platform. A charger maintains a persistent WebSocket connection to the backend to report status, start/stop charging sessions, receive firmware and configuration commands, and relay metering data. Because this channel exists specifically to let a remote charger act on the backend's behalf, the backend must be able to verify that the party on the other end of the WebSocket really is the charger it claims to be.
Root cause
Per NVD, the Monta platform fails to perform that verification: WebSocket connections are accepted based solely on the station ID presented by the connecting client, with no authentication mechanism enforced on top of it. OCPP 1.6 defines an optional Security Profile mechanism for exactly this purpose — Security Profile 1 (no transport security), Security Profile 2 (HTTP Basic Auth over TLS), and Security Profile 3 (mutual TLS with client certificates) — but reporting on this advisory indicates Monta's deployment did not enforce a credentialed profile, leaving the station ID as the only distinguishing value on the connection.
That alone would be a weak-credential problem; the companion finding CVE-2026-93474 (station identifiers exposed via public charging-map platforms) turns it into a trivial one. An attacker does not need to guess or brute-force a station ID — they can look one up on a public map of charging locations and use it directly.
Attack chain
1. Attacker looks up a valid charging-station ID from a public
EV-charging map or directory (CVE-2026-93474).
2. Attacker opens a WebSocket connection to Monta's OCPP backend
endpoint, presenting that station ID with no other credential.
3. The backend accepts the connection and treats the attacker's
session as if it were the genuine charging station.
4. The attacker can now send OCPP messages the backend expects
only from a trusted charge point — e.g. status/meter reports,
session start/stop, or firmware/configuration responses — and
receive whatever the backend sends to that station, including
session and user data tied to charging activity at that point.Why this matters for OT/ICS
EV charging platforms are a growing category of consumer-facing OT: the backend is cloud software, but the thing being controlled is physical hardware delivering real electrical power to vehicles. CISA's advisory places Monta under the Energy and Transportation Systems critical-infrastructure sectors for that reason. Successful impersonation of a charge point does not just leak data — depending on what the backend trusts an authenticated charge point to report or request, it can affect session integrity (billing/metering manipulation), availability (disabling or disrupting a charger), and in the worst case physical safety parameters tied to power delivery. The 9.4 score and CWE-306 classification reflect that this is a complete authentication bypass on a function that was designed to be trust-critical, not a lesser access-control gap.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Rated High — an impersonated session can expose charging-session logs, user/payment association data, location/usage history, and vehicle identifiers that flow between the charger and backend |
| Integrity | Rated High — an attacker posing as a charge point can submit falsified status, metering, or session data, and potentially act on commands the backend would otherwise reserve for the real device |
| Availability | Rated Low (per the CVSS v3.1 vector) — disruption is possible (e.g. disabling a charger's reporting) but less severe than the confidentiality/integrity impact |
| Physical / OT Risk | EV chargers deliver real electrical power; a trust relationship built on an unauthenticated, publicly-known station ID removes a safety and control boundary between the internet and physical charging hardware |
| Vulnerability Chaining | Combined with CVE-2026-93474 (public station-ID exposure) and CVE-2026-97363 (no rate limiting on auth attempts), this CVE is part of a bundle that materially lowers the effort needed to reach a working impersonation |
| Fleet-Wide Exposure | Affects all versions of the platform per the advisory — this is a design/configuration issue in how the backend accepts connections, not a bug isolated to a specific release |
Recommendations
For Monta operators and charging-station owners
- Enable OCPP 1.6 Security Profile 2 (HTTP Basic Auth over TLS) on every station, using a long, unique password that is not derived from or related to the public station ID. Reporting on this advisory is explicit that the station ID alone must not remain the only credential.
- Treat every publicly listed station ID as already compromised for authentication purposes — if a mapping platform shows it, assume an attacker has it, and ensure your authentication does not depend on its secrecy.
- Where supported, move to OCPP 1.6 Security Profile 3 (mutual TLS with client certificates) or OCPP 2.0.1, which provide stronger, certificate-based device identity instead of a shared credential.
- Review charging-session and billing logs for anomalies — unexpected session starts/stops, metering values inconsistent with real usage, or connections from unexpected source IPs for a given station ID.
For OT/ICS security and critical-infrastructure teams
- Inventory EV charging infrastructure connected to cloud management platforms the same way you would any other OT asset — charge points are internet-connected hardware with real-world physical effects.
- Apply the CISA ICSA-26-274-02 advisory in full, not just this CVE — the bundled rate-limiting (CVE-2026-97363) and session-expiration (CVE-2026-97212) issues compound the impersonation risk and should be mitigated together.
- Monitor for station-ID reuse or concurrent connections from multiple source locations claiming the same charger identity, which would indicate active impersonation.
For OCPP implementers and EV charging platform vendors
- Never treat a protocol-level device identifier (station ID, charge-point ID, serial number) as a credential. Device identity and authentication are separate concerns; OCPP's Security Profile mechanism exists precisely to keep them separate.
- Default new deployments to the strongest available Security Profile rather than leaving authentication opt-in — this advisory is a direct consequence of a weaker profile being reachable (or default) in production.
- Assume any identifier surfaced on a public map, app, or directory is public information and design authentication accordingly.
Key Takeaways
- CVE-2026-95102 is a CVSS 9.4 Critical missing-authentication flaw (CWE-306) in Monta's monta.app EV charging platform, affecting all versions.
- The root cause is that OCPP WebSocket connections are accepted using only the charging station's ID, with no enforced credential — and that ID is publicly discoverable via charging-map platforms (a separate, related CVE-2026-93474).
- This is an OT/ICS-adjacent vulnerability: the backend is cloud software, but impersonating a charge point can affect real physical charging hardware and the data tied to it, which is why CISA issued a dedicated ICS advisory (ICSA-26-274-02) covering it and three related CVEs.
- There is no version-specific patch — the documented mitigation is a configuration change: enabling OCPP 1.6 Security Profile 2 (or stronger) with a unique per-station credential unrelated to the public station ID.
- No public exploit code has been identified and the CVE is not in CISA's KEV catalog as of October 3, 2026, but the low attack complexity and lack of required privileges make this a high-priority fix for any Monta-connected charging operator.
- Public technical detail beyond the NVD record and CISA advisory comes from third-party security-research writeups; CosmicBytez Labs will update this advisory if Monta publishes its own security bulletin or a more detailed technical disclosure.
Sources
- NVD — CVE-2026-95102
- CISA — ICS Advisory ICSA-26-274-02
- TheHackerWire — Unauthenticated WebSocket Impersonation Enables Charging Station Compromise
- Strix.ai — CVE-2026-95102: monta.app Missing Authentication (CVSS 9.4)
- dev.to — Monta EV charging flaws: chargers can be impersonated (CVSS 9.4)
CosmicBytez Labs will update this advisory if Monta or CISA publish additional technical detail or a versioned fix for CVE-2026-95102.