Description
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability in Kener allows an unauthenticated attacker to read hidden or inactive monitor data. By sending requests to dashboard API endpoints that lack proper visibility filters, an attacker can retrieve the monitor’s name, description, status, uptime history and latency. This is a classic information disclosure weakness (CWE-200), exposing sensitive operational data to anyone who can reach the API.

Affected Systems

The affected product is Kener, version 4.0.0 up to and including 4.1.5. These releases are hosted by the vendor rajnandan1 and provide the dashboard API that is susceptible to the data disclosure flaw.

Risk and Exploitability

The flaw carries a CVSS score of 6.9, indicating a medium‑to‑high risk level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a remote, unauthenticated network request to the open API endpoints. Once the attacker supplies a known or guessed monitor tag, the missing visibility checks allow the disclosure, making the issue exploitable without any privilege escalation or additional configuration.

Generated by OpenCVE AI on October 3, 2026 at 00:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check vendor for updates or patches
  • Configure the dashboard API to enforce visibility filters on monitor data
  • Restrict API access to trusted users or networks

Generated by OpenCVE AI on October 3, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Title Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:49.929Z

Reserved: 2026-10-02T21:13:54.716Z

Link: CVE-2026-105030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T00:16:36.743

Modified: 2026-10-03T00:16:36.743

Link: CVE-2026-105030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T01:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor