Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests. | |
| Title | Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2026-08-14T19:43:32.897Z
Reserved: 2026-06-24T13:49:50.681Z
Link: CVE-2026-57469
Updated: 2026-08-14T19:43:28.306Z
Status : Received
Published: 2026-08-14T16:16:58.043
Modified: 2026-08-14T20:16:53.940
Link: CVE-2026-57469
No data.
OpenCVE Enrichment
Updated: 2026-08-14T17:00:15Z