Cross-Site Request Forgery in KUNBUS PiCtory Web-Based Configuration
CVE-2026-57469
5.1MEDIUM
What is CVE-2026-57469?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web-based configuration backend of KUNBUS PiCtory version 2.16.0. This flaw allows a remote unauthenticated attacker to exploit the security context of an authenticated operator. By tricking the operator's browser into sending crafted requests, the attacker can perform state-changing operations. This includes the deletion of project and configuration files and resetting the control runtime, potentially leading to severe disruptions in operations. Users of KUNBUS PiCtory are advised to take immediate actions to mitigate this vulnerability.
Affected Version(s)
PiCtory 0 <= 2.16.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Quagliarella at Nozomi Networks
