VDB
CVE-2026-81573
CVE-2026-81573
PUBLISHED
CVSS 8.6 HIGH
Reported by wibu · Published August 27, 2026
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.
Risk Scores
CVSS 3.1
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wibu-systems-ag | codemeter-runtime | 9.00, 8.00, 7.x |
| wibu-systems-ag | codemeter-runtime | 9.00, 8.00 |
| wibu-systems-ag | codemeter-runtime | 9.00, 8.00, 7.x |
Timeline
- Aug 27, 2026 EPSS Score
- Aug 27, 2026 Coalition ESS Score
- Aug 27, 2026 CVE Published
- Aug 27, 2026 CVE Updated
- Sep 1, 2026 EPSS Score