What is CVE-2026-57471?
A Path Traversal (CWE-22) vulnerability was identified in the XML-RPC management interface of KUNBUS RevPiPyLoad version 0.11.0. This flaw allows a local unauthenticated attacker to read files outside the restricted directory via the file management functionality. Immediate update of the software is recommended.
Azərbaycanca: KUNBUS RevPiPyLoad proqramının 0.11.0 versiyasında XML-RPC idarəetmə interfeysində Path Traversal (CWE-22) zəifliyi aşkar edilib. Bu, lokal və autentifikasiya olunmamış hücumçuya fayl idarəetmə funksiyası vasitəsilə məhdud qovluqdan kənar faylları oxumağa imkan verir. Təcili olaraq proqramı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendors: KUNBUS, Nozomi Networks
FAQ2
In which product was CVE-2026-57471 identified and what is its root cause?
This vulnerability was identified as a Path Traversal (CWE-22) in the XML-RPC management interface of KUNBUS RevPiPyLoad version 0.11.0.
What can a local attacker achieve by exploiting CVE-2026-57471?
A local unauthenticated attacker can read files outside the restricted directory via the file management functionality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.