Vulnerability Description
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-57469?
CVE-2026-57469 is a documented vulnerability. Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticat...
How severe is CVE-2026-57469?
CVSS scoring is not yet available for CVE-2026-57469. Check NVD for updates.
Is there a patch for CVE-2026-57469?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.