CVE-2026-13196: Out-of-bounds Write in KUNBUS piControl
Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13196?
CVE-2026-13196 has a risk score of 48.
How do I fix CVE-2026-13196?
To fix CVE-2026-13196, update KUNBUS piControl to the latest version that addresses this vulnerability.
Who can exploit CVE-2026-13196?
CVE-2026-13196 can be exploited by a local authenticated attacker with device configuration access.
What does CVE-2026-13196 affect?
CVE-2026-13196 affects the process-image management functionality of KUNBUS piControl version 2.6.2.
What type of vulnerability is CVE-2026-13196?
CVE-2026-13196 is classified as a CWE-787: Out-of-bounds Write vulnerability.