CVE-2026-13197
A CWE-362: Race Condition in piControl at v2.6.2 allows configuration reset races to trigger use-after-free and invalid kernel pointer dereferences.
This issue allows a local authenticated attacker to corrupt kernel memory and cause denial of service.
July 6, 2026
KUNBUS piControl v2.6.2
CVE-2026-13197
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.3
To fix this issue, it is suggested to upgrade to picontrol version 2.8.0
Gabriele Quagliarella at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more