VDB

CVE-2026-81573

CVE-2026-81573 PUBLISHED CVSS 8.6 HIGH

Reported by wibu · Published August 27, 2026

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

Risk Scores

CVSS 3.1
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Affected Products

VendorProductVersions
wibu-systems-agcodemeter-runtime9.00, 8.00, 7.x
wibu-systems-agcodemeter-runtime9.00, 8.00
wibu-systems-agcodemeter-runtime9.00, 8.00, 7.x

Timeline

  • Aug 27, 2026 EPSS Score
  • Aug 27, 2026 Coalition ESS Score
  • Aug 27, 2026 CVE Published
  • Aug 27, 2026 CVE Updated
  • Sep 1, 2026 EPSS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›