CVE-2026-81581
Received Received - Intake

Improper Memory Validation in WibuKey Driver

Vulnerability report for CVE-2026-81581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: 2fc02b1f-71e7-4514-a878-169626f68903

Description

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
wibu-systems_ag wibukey 6.70
wibu-systems_ag wibukey to 6.71 (exc)
wibukey wibukey to 6.70 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in WibuKey software for Windows versions prior to 6.71. It involves improper validation of memory boundaries in the WibuKey64.sys driver. An attacker can manipulate pointers to access any storage location, potentially causing a denial of service or even remote code execution and privilege escalation since the driver runs with system privileges.

Detection Guidance

Detecting this vulnerability requires checking the version of WibuKey installed on your system. Compare the installed version against 6.71 or later. The vulnerable driver WibuKey64.sys runs with system privileges, so inspecting system drivers may help identify it.

Impact Analysis

This vulnerability can lead to denial of service on your system. Due to the driver running with system privileges, there is also a risk of remote code execution or privilege escalation, which could allow attackers to gain full control over your system.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA due to its ability to cause denial of service, remote code execution, or privilege escalation. Since the WibuKey64.sys driver runs with system privileges, unauthorized access could lead to data breaches or system compromise, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Immediately update WibuKey to version 6.71 or later as recommended by the vendor. Since the driver runs with system privileges, ensure no untrusted users or processes can interact with it until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart