CodeMeter Runtime Server Vulnerability Exposing Configuration to Unauthorized Access
CVE-2026-81573
8.6HIGH
What is CVE-2026-81573?
A vulnerability exists in the CodeMeter Runtime versions prior to 8.41a and 9.10 when configured as a server. The configuration command handler fails to enforce network-origin restrictions, allowing arbitrary remote peers to execute commands intended solely for local or same-network clients. This flaw poses a risk where an attacker can access sensitive configuration data and modify select parameters within Server.ini, which includes credentials' hashed values for the CodeMeter WebAdmin. Consequently, this can lead to unauthorized access and potential takeover of the WebAdmin interface.
Affected Version(s)
codemeter-runtime 9.00 < 9.10
codemeter-runtime 8.00 < 8.41a
codemeter-runtime 7.x
