Local Privilege Escalation Vulnerability in CodeMeter by Wibu Systems
CVE-2026-81572

7.8HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81572?

A vulnerability exists in the CodeMeter Runtime where it creates predictable temporary files under C:\CM-Stick. Due to improper checks for NTFS reparse points like junctions or symbolic links during file operations, a local attacker could exploit this flaw. By creating a junction at the temporary file location that redirects to an arbitrary system path, the attacker gains the ability to delete arbitrary files with System privileges. Since CodeMeter Runtime operates under these elevated rights, this creates a pathway for local privilege escalation that could compromise the integrity of the system.

Affected Version(s)

codemeter-runtime Windows 8.40 < 8.41a

codemeter-runtime Windows 9.00 < 9.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andreas Vikerup of Shelltrail AB
.