CVE-2026-81573 HIGH

CVE-2026-81573: Improper Access Control in Local-Only Configuration Commands

Vendor Wibu-Systems-Ag
Product codemeter-runtime
Weakness CWE-284
Published August 27, 2026
Last update August 27, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE