What is CVE-2026-57469?
This is a Cross-Site Request Forgery (CSRF) vulnerability found in the web-based configuration backend of KUNBUS PiCtory version 2.16.0. It allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator. Immediately apply the security update provided by the vendor.
Azərbaycanca: Bu, KUNBUS PiCtory 2.16.0 veb interfeysində aşkar edilmiş CSRF (Cross-Site Request Forgery) zəifliyidir. Uzaqdan autentifikasiya olunmamış hücumçuya autentifikasiya olunmuş operatorun sessiyasında konfiqurasiyanı dəyişmək kimi əməliyyatlar aparmağa imkan verir. Təcili olaraq istehsalçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: KUNBUS, Nozomi Networks
FAQ2
In which product was CVE-2026-57469 discovered?
In the web-based configuration backend of KUNBUS PiCtory version 2.16.0.
What can an attacker achieve by exploiting this CSRF vulnerability?
A remote unauthenticated attacker can perform state-changing operations in the context of an authenticated operator.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.