CVE-2026-57469

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-14 16:16

Updated : 2026-08-28 19:46


NVD link : CVE-2026-57469

Mitre link : CVE-2026-57469

CVE.ORG link : CVE-2026-57469


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)