Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105030— Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API

Quick assessment

Affected
rajnandan1 kener
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kener 4.0.0 至 4.1.6(不含 4.1.6)版本中存在一个信息泄露漏洞。该漏洞允许未认证的攻击者通过查询缺少可见性过滤器的 Dashboard API 处理程序,获取隐藏或已停用的监控数据。攻击者可以使用已知或猜測的监控标签,向诸如 monitor-bar 和 monitor-latency-chart 等端点发起请求,从而获取监控项的名称、描述、状态、运行历史记录以及延迟信息。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105030

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Source: CVE Program / CVE List V5
Vulnerability Description
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rajnandan1 kener 4.0.0 ~ 4.1.6 -

II. Public POCs for CVE-2026-105030

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105030

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-105030 (1)

Vendor Advisories for CVE-2026-105030 (1)

News Coverage for CVE-2026-105030 (1)

Other References for CVE-2026-105030 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105030

No comments yet


Leave a comment