CodeMeter Runtime Vulnerability in Wibu-Systems Software
CVE-2026-81576

7.7HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81576?

The CodeMeter Runtime prior to versions 8.41a and 9.10 contains a vulnerability where the software, when configured as a server, utilizes a cryptographically weak Session ID (SID) as the sole method of client authentication. This weakness enables attackers to potentially conduct brute-force attacks against the SID, allowing them to recover session handle numbers linked to other connections. With this information, unauthorized users may access and read sensitive license information associated with other user sessions, posing serious security risks for organizations relying on this software.

Affected Version(s)

codemeter-runtime 9.00 < 9.10

codemeter-runtime 8.00 < 8.41a

codemeter-runtime 7.00

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Teylu of Vector Informatik GmbH
.