CVE-2026-81575
Received Received - Intake

CodeMeter Runtime Out-of-Bounds Read Vulnerability

Vulnerability report for CVE-2026-81575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: 2fc02b1f-71e7-4514-a878-169626f68903

Description

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wibu_systems codemeter_runtime to 8.41a|start_including=9.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in CodeMeter Runtime versions before 8.41a and 9.10 when configured as a server. It involves accepting requests with opcode 0x5e that include data length and data. The issue is missing bounds checking on the data length, which can lead to out of bounds reads. This causes a segmentation fault and crashes the CodeMeter Runtime.

Detection Guidance

This vulnerability can be detected by monitoring CodeMeter Runtime processes for crashes or segmentation faults. Check for unexpected termination of the CodeMeter service. Inspect network traffic for opcode 0x5e requests to CodeMeter servers. Ensure CodeMeter Runtime is updated to versions 8.41a or 9.10 or later to mitigate the issue.

Impact Analysis

The vulnerability can cause the CodeMeter Runtime to crash due to segmentation faults, leading to denial of service. Since it affects server configurations, it may disrupt services relying on CodeMeter for license management or protection.

Compliance Impact

This vulnerability causes a segmentation fault and crash in CodeMeter Runtime due to missing bounds checking, which could lead to denial of service. Such disruptions may impact systems handling sensitive data, potentially affecting compliance with GDPR or HIPAA by compromising availability or integrity of protected information.

Mitigation Strategies

Update CodeMeter Runtime to versions 8.41a or 9.10 or later to address the missing bounds checking issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart