CVE-2026-57469 MEDIUM

CVE-2026-57469: Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory

Vendor Kunbus
Product PiCtory
Weakness CWE-352 · CSRF
Published August 14, 2026
Last update August 14, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L

What the vulnerability does

01Description

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.

Key dates

02Disclosure timeline

August 14, 2026 CVE published
August 14, 2026 Record updated

Related vulnerabilities

04Related CVE