rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9

CVE-2026-105030

Kener 4.0.0 and earlier versions expose hidden or inactive monitor data through dashboard API endpoints that lack proper visibility filters.

Overview

Kener 4.0.0 and earlier versions expose hidden or inactive monitor data through dashboard API endpoints that lack proper visibility filters. Unauthenticated attackers can retrieve sensitive monitor metadata such as names, descriptions, status, uptime history, and latency by guessing monitor tags. This flaw allows attackers to gain insight into system performance and configuration without needing credentials.

Description

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.

Impact

The vulnerability compromises the confidentiality of monitoring data, potentially revealing operational details that could aid further attacks. It does not affect availability or integrity directly. System administrators and security teams are the primary defenders impacted, as they must secure or patch the exposed APIs.

Remediation

Apply the official patch to Kener 4.1.6 or later to fix the visibility filter issue. If patching is delayed, restrict API access to authenticated users only, enforce strict role-based access controls, and disable or remove endpoints that expose monitor tags. Additionally, implement network segmentation to limit exposure of the monitoring API to trusted internal networks.

Risk context

The CVSS v3 score of 5.3 and v4 score of 6.9 classify this as medium severity. With no EPSS data available, the risk remains moderate but should be addressed promptly to prevent information leakage.

Affected products

  • Kener 4.0.0
  • Kener 4.1.5

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
—

information-disclosure monitor-data unauthenticated Kener API medium-severity patch-needed

← All CVEs