Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.3%
from disclosure to weapon1 days
Published on NVDOct 2
1st PoC+1d
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
rajnandan1 · kenerpublic PoCs found — 1
githubgithub.com/asvorg/CVE-2026-105030-poc★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.