Cross-Site Request Forgery in KUNBUS PiCtory Web-Based Configuration
CVE-2026-57469

5.1MEDIUM

Key Information:

Vendor

Kunbus

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-57469?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web-based configuration backend of KUNBUS PiCtory version 2.16.0. This flaw allows a remote unauthenticated attacker to exploit the security context of an authenticated operator. By tricking the operator's browser into sending crafted requests, the attacker can perform state-changing operations. This includes the deletion of project and configuration files and resetting the control runtime, potentially leading to severe disruptions in operations. Users of KUNBUS PiCtory are advised to take immediate actions to mitigate this vulnerability.

Affected Version(s)

PiCtory 0 <= 2.16.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Quagliarella at Nozomi Networks
.