CVE-2026-81576
Received Received - Intake

CodeMeter Runtime Session Key Exposure Vulnerability

Vulnerability report for CVE-2026-81576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: 2fc02b1f-71e7-4514-a878-169626f68903

Description

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wibu_systems codemeter_runtime to 8.41a|start_including=9.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CodeMeter Runtime before versions 8.41a and 9.10 has a server configuration issue where it uses a cryptographically weak SID for authentication. This allows attackers to brute-force the SID, recover session handle numbers, and access license information from other sessions.

Detection Guidance

This vulnerability involves weak SID authentication in CodeMeter Runtime when configured as a server. Detection requires monitoring for unusual license information access patterns or brute-force attempts against SIDs. Check CodeMeter Runtime logs for repeated failed authentication attempts or unexpected handle access. Inspect network traffic for unencrypted SID exchanges between clients and servers.

Impact Analysis

An attacker could exploit this to read sensitive license information belonging to other users or systems connected to the CodeMeter server. This may lead to unauthorized access to proprietary software licenses or data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing confidential license or user information.

Mitigation Strategies

Update CodeMeter Runtime to versions 8.41a or 9.10 or later to address the weak SID authentication issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart