CVE-2026-81576

Summary

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

Affected Software

VendorProductVersion RangeStatus
wibu-systems-agcodemeter-runtime9.00 < 9.10affected
wibu-systems-agcodemeter-runtime8.00 < 8.41aaffected
wibu-systems-agcodemeter-runtime7.00affected
wibu-systems-agcodemeter-runtime6.00affected

Weaknesses

  • CWE-639: CWE-639 Authorization bypass through User-Controlled key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References