CVE-2026-105030

Source
https://cve.org/CVERecord?id=CVE-2026-105030
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105030.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105030
Published
2026-10-02T23:28:49Z
Modified
2026-10-04T02:46:02Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Details

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-200"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105030.json"
}
References

Affected packages

Git / github.com/rajnandan1/kener

Affected ranges

Type
GIT
Repo
https://github.com/rajnandan1/kener
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.0.0"
        },
        {
            "fixed":  "4.1.6"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v4.*
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.13
v4.0.14
v4.0.15
v4.0.16
v4.0.17
v4.0.18
v4.0.2
v4.0.20
v4.0.21
v4.0.22
v4.0.23
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105030.json"