CVE-2026-13197
7.3KUNBUS · piControl
A race condition vulnerability in the configuration and process-image management of KUNBUS piControl versions 0 through 2.6.2 may allow local authenticated attackers to disrupt system operations.
Executive summary
A race condition vulnerability in KUNBUS piControl versions 0 through 2.6.2 enables locally authenticated attackers to compromise system integrity through improper resource synchronization.
Vulnerability
The software contains a race condition (CWE-362) within its configuration and process-image management modules, caused by improper synchronization when accessing shared resources. This allows a local attacker with low privileges (PR:L) to trigger the flaw under specific timing conditions.
Business impact
A successful exploit could lead to inconsistent system states, denial of service, or unauthorized modification of process data. With a CVSS score of 7.3, this vulnerability threatens the reliability of the industrial processes managed by the piControl software.
Remediation
Immediate Action: Consult the vendor for security patches that address synchronization issues in the configuration management module.
Proactive Monitoring: Monitor for unusual CPU spikes or synchronization errors in system logs that may correlate with attempts to exploit race conditions.
Compensating Controls: Implement strict access control policies to ensure that only trusted users have local access to the system, thereby reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Immediate attention is required to patch this vulnerability to ensure the continued integrity of the piControl environment. Organizations should verify their current version and coordinate with KUNBUS support to apply the most current security updates.