Search
Find a vulnerability
Search criteria
1 vulnerability by rajnandan1
CVE-2026-105030 (GCVE-0-2026-105030)
Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
VLAI
EPSS
VEX
Title
Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Summary
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Severity
5.3 (Medium)
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/rajnandan1/kener/issues/848 | issue-tracking |
| https://github.com/rajnandan1/kener/commit/e8ce31… | patch |
| https://github.com/rajnandan1/kener | product |
| https://www.vulncheck.com/advisories/kener-4.0.0-… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| rajnandan1 | kener |
Affected:
4.0.0 , < 4.1.6
(semver)
Unaffected: 4.1.6 (semver) |
Date Public
2026-09-16 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "kener",
"repo": "https://github.com/rajnandan1/kener",
"vendor": "rajnandan1",
"versions": [
{
"lessThan": "4.1.6",
"status": "affected",
"version": "4.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.1.6",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T23:28:49.929Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #848",
"tags": [
"issue-tracking"
],
"url": "https://github.com/rajnandan1/kener/issues/848"
},
{
"tags": [
"patch"
],
"url": "https://github.com/rajnandan1/kener/commit/e8ce31898bf73ffe6be07c9b299da2a7330ddba5"
},
{
"tags": [
"product"
],
"url": "https://github.com/rajnandan1/kener"
},
{
"name": "VulnCheck Advisory: Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/kener-4.0.0-before-4.1.6-hidden-monitor-data-disclosure-via-dashboard-api"
}
],
"title": "Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105030",
"datePublished": "2026-10-02T23:28:49.929Z",
"dateReserved": "2026-10-02T21:13:54.716Z",
"dateUpdated": "2026-10-02T23:28:49.929Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}