CodeMeter Runtime Vulnerability in Wibu-Systems Software
CVE-2026-81576
7.7HIGH
What is CVE-2026-81576?
The CodeMeter Runtime prior to versions 8.41a and 9.10 contains a vulnerability where the software, when configured as a server, utilizes a cryptographically weak Session ID (SID) as the sole method of client authentication. This weakness enables attackers to potentially conduct brute-force attacks against the SID, allowing them to recover session handle numbers linked to other connections. With this information, unauthorized users may access and read sensitive license information associated with other user sessions, posing serious security risks for organizations relying on this software.
Affected Version(s)
codemeter-runtime 9.00 < 9.10
codemeter-runtime 8.00 < 8.41a
codemeter-runtime 7.00
