CVE-2026-81574
Received Received - Intake

CodeMeter Runtime Format String Vulnerability

Vulnerability report for CVE-2026-81574, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: 2fc02b1f-71e7-4514-a878-169626f68903

Description

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wibu_systems codemeter to 9.10 (exc)
wibu_systems codemeter_runtime to 8.41a|start_including=9.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-134 The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input sanitization in the CodeMeter Runtime logger. Attackers can inject printf-style format specifiers into strings, causing crashes or exposing sensitive memory data like stack canaries. The flaw exists in versions before 8.41a and 9.10.

Detection Guidance

Detection involves checking for CodeMeter Runtime versions before 8.41a or 9.10. Inspect installed versions via system package managers or CodeMeter Control Center. Monitor logs for crashes or format string anomalies during proxy-related operations.

Impact Analysis

An attacker could crash CodeMeter processes or leak sensitive information such as memory contents. The attack can occur locally via commands like cmu --set-proxy or remotely when combined with another vulnerability (CVE-2026-81573).

Compliance Impact

This vulnerability could lead to disclosure of sensitive information such as process memory and stack canaries, which may include personal or confidential data. This could potentially violate GDPR (if personal data is exposed) and HIPAA (if protected health information is compromised).

Mitigation Strategies

Update CodeMeter Runtime to versions 8.41a or 9.10 or later immediately. Disable proxy settings if not required. Restrict local and remote access to CodeMeter services until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart