---
title: "Kunbus-2026-0000009: Multiple Vulnerabilities in KUNBUS Packages for Revolution Pi - Revolution Pi"
url: "https://revolutionpi.com/de/support/security-advisories/kunbus-2026-0000009"
date: 2026-07-28
modified: 2026-07-29
---

# Kunbus-2026-0000009: Multiple Vulnerabilities in KUNBUS Packages for Revolution Pi - Revolution Pi

27.07.2026

Kunbus-2026-0000009: Multiple Vulnerabilities in KUNBUS Packages for Revolution Pi
==================================================================================

**TLP: WHITE**

 | Publisher: KUNBUS PSIRT | Document category: csaf\_security\_advisory |
|---|---|
| Initial release date: 2026-07-27T14:39:00.926463392Z | Engine: csaf-cms-backend 1.0.0-kunbus.1 |
| Current release date: 2026-07-27T14:39:00.926463392Z | Build Date: 2026-07-27T14:31:23.202Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 7.1 | Severity: |
| Original language: | Language: en-US |
| Also referred to: |

Vulnerabilities
---------------

### CSRF in Pictory (CVE-2026-57469)

 **Description**The pictory web config tool has a CSRF vulnerability that could enable a attacker to take over a session and perform actions on behalf of the logged in user.

 | CWE: | CWE-352:Cross-Site Request Forgery (CSRF) |
|---|---|

#### Product status

##### Known affected

 | Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS Pictory vers:deb/<=2.16.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L | 5.4 |

##### Fixed

- KUNBUS Pictory 2.17.0

#### Remediations

##### Vendor fix (2026-07-13T10:00:00.000Z)

Update to Pictory Version 1.17.0

###### For products:

- KUNBUS Pictory vers:deb/<=2.16.0

#### References

- Nozomi Networks security advisory NN-2026-123 (external) [https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57469](https://revolutionpi.com/https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57469)

### Possible Extraction of files with the rights of the default user in revpipyload (CVE-2026-57471)

 **Describtion**An attacker that can access revpipyload XML-RPC interface can gain access to all files the revpipyload process has access to due to improper path checks for the download endpoint.

 | CWE: | CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|---|---|

#### Product status

##### Known affected

 | Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS revpipyload vers:deb/<= 0.11.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 5.5 |

##### Fixed

- KUNBUS revpipyload 0.11.1

#### Remediations

##### Vendor fix (2026-07-13T10:00:00.000Z)

Update to revpipyload 0.11.1

###### For products:

- KUNBUS revpipyload vers:deb/<= 0.11.0

#### References

- Nozomi Networks security advisory NN-2026-0125 (external) [https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57471](https://revolutionpi.com/https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57471)

### Possible Deletion of files with the rights of default user for a locally authenticated attacker (CVE-2026-57472)

 **Description**An attacker with access to the revpipyload XML-RPC interface can delete all files the revpipyload process has access rights.

 | CWE: | CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|---|---|

#### Product status

##### Known affected

 | Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS revpipyload vers:deb/<= 0.11.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H | 7.1 |

##### Fixed

- KUNBUS revpipyload 0.11.1

#### Remediations

##### Vendor fix (2026-07-13T10:00:00.000Z)

Update to revpipyload 0.11.1

###### For products:

- KUNBUS revpipyload vers:deb/<= 0.11.0

#### References

- Nozomi Networks security advisory NN-2026-0126 (external) [https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57472](https://revolutionpi.com/https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57472)

Acknowledgments
---------------

 KUNBUS PSIRT thanks the following parties for their efforts: - Gabriele Quagliarella from Nozomi Networks

KUNBUS PSIRT
------------

Namespace: https://www.kunbus.com

product-security@kunbus.com

KUNBUS GmbH develops and produces the Revolution Pi Family, Revolution Pi OS and the extension modules for RevPi amongst others. KUNBUS PSIRT is responsible for vulnerability handling across all KUNBUS products and services.

References
----------

- URL generated by system (self) [https://psirt.kunbus.com/white/2026/kunbus-2026-0000009.json](https://revolutionpi.com/https://psirt.kunbus.com/white/2026/kunbus-2026-0000009.json)

Revision history
----------------

 | Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-07-27T14:39:00.926463392Z | Initial Publication |

Sharing rules
-------------

 **TLP:WHITE**
 For the TLP version see: [https://www.first.org/tlp/](https://revolutionpi.com/https://www.first.org/tlp/)

Legal Disclaimer
----------------

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. KUNBUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.