CVE-2026-105030: RAJNANDAN1 Kener

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.

Affected products

  • RAJNANDAN1 Kener: from 4.0.0, before 4.1.6 (fixed in 4.1.6)

Published 2026-10-03. Last modified 2026-10-06.