Input Sanitization Flaw in CodeMeter Runtime by Wibu-Systems
CVE-2026-81574

8.2HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81574?

The CodeMeter Runtime prior to versions 8.41a and 9.10 is susceptible to an input sanitization flaw that allows attackers to inject printf-style format specifiers. This vulnerability can trigger application crashes and expose sensitive information such as process memory and stack canaries. The exploitation can occur locally via command-line utilities or remotely alongside related vulnerabilities, posing a significant risk to system integrity.

Affected Version(s)

codemeter-runtime 9.00 < 9.10

codemeter-runtime 8.00 < 8.41a

codemeter-runtime 7.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Teylu of Vector Informatik GmbH
.