AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-57469

MEDIUM · CVSS 5.1

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web-based configuration backend of KUNBUS PiCtory version 2.16.0, allowing remote unauthenticated attackers to execute state-changing operations as an authenticated user. This could lead to the deletion of project files and configuration settings, as well as the reset of the control runtime. Organizations using this version should prioritize remediation to mitigate potential unauthorized access and data loss.

CVE
CVE-2026-57469
Severity
MEDIUM
CVSS
5.1
EPSS
N/A

Original NVD Description

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.