CVE-2026-105030
Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
| CWE | CWE-200 |
| Vendor | rajnandan1 |
| Product | kener |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for rajnandan1 kener
Be the first to know when new medium vulnerabilities affecting rajnandan1 kener are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
rajnandan1 / kener
4.0.0 < 4.1.6
References
github.com: https://github.com/rajnandan1/kener/issues/848 github.com: https://github.com/rajnandan1/kener/commit/e8ce31898bf73ffe6be07c9b299da2a7330ddba5 github.com: https://github.com/rajnandan1/kener vulncheck.com: https://www.vulncheck.com/advisories/kener-4.0.0-before-4.1.6-hidden-monitor-data-disclosure-via-dashboard-api
Credits
George Chen