CVE-2026-13198
A CWE-362: Race Condition in piControl at v2.6.2 allows concurrent event waiters to corrupt kernel heap and event-list state.
This issue allows a local authenticated attacker to disclose adjacent kernel data and cause denial of service.
July 6, 2026
KUNBUS piControl v2.6.2
CVE-2026-13198
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
5.9
To fix this issue, it is suggested to upgrade to picontrol version 2.8.0
Gabriele Quagliarella at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more