CVE-2026-57469
A CWE-352: Cross-Site Request Forgery in PiCtory at v2.16.0 allows remote attackers to perform actions through an authenticated operator's browser.
This issue allows a remote attacker to delete project files, reset the control runtime, and invoke other protected operations.
July 6, 2026
KUNBUS PiCtory v2.16.0
CVE-2026-57469
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
5.1
To fix this issue, it is suggested to update to Pictory version 1.17.0
Gabriele Quagliarella at Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more