Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests. | |
| Title | Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-08-14T15:03:32.185Z
Reserved: 2026-06-24T13:49:50.681Z
Link: CVE-2026-57469
No data.
Status : Received
Published: 2026-08-14T16:16:58.043
Modified: 2026-08-14T16:16:58.043
Link: CVE-2026-57469
No data.
OpenCVE Enrichment
No data.