CodeMeter Runtime Server Vulnerability Exposing Configuration to Unauthorized Access
CVE-2026-81573

8.6HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81573?

A vulnerability exists in the CodeMeter Runtime versions prior to 8.41a and 9.10 when configured as a server. The configuration command handler fails to enforce network-origin restrictions, allowing arbitrary remote peers to execute commands intended solely for local or same-network clients. This flaw poses a risk where an attacker can access sensitive configuration data and modify select parameters within Server.ini, which includes credentials' hashed values for the CodeMeter WebAdmin. Consequently, this can lead to unauthorized access and potential takeover of the WebAdmin interface.

Affected Version(s)

codemeter-runtime 9.00 < 9.10

codemeter-runtime 8.00 < 8.41a

codemeter-runtime 7.x

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Teylu of Vector Informatik GmbH
.