Junglewise Threat Intelligence

CVE-2026-81572: Wibu-Systems CodeMeter Runtime insecure temporary file in cmu.exe

CVE-2026-81572 · Severity: high · CVSS 7.8 · Published 2026-08-27

Technologies: Wibu-Systems CodeMeter Runtime. Vendors: Wibu-Systems.

Executive brief

CodeMeter Runtime is a license management system used by software publishers to protect and monetize their applications. The vulnerability allows a local attacker to create symbolic links or junctions pointing to arbitrary system locations, which can result in deletion of sensitive files or privilege escalation, since CodeMeter runs with System-level privileges. This could compromise system integrity and enable unauthorized administrative access.

Technical details

The vulnerability is a local privilege escalation flaw in the cmu.exe command-line utility (versions 8.40–8.41a and 9.00–9.10). When invoked with the --create-io --file C: flag, cmu.exe creates a predictable temporary file in C:\CM-Stick without properly validating for NTFS reparse points such as junctions or symbolic links. An unauthenticated local attacker can pre-create a junction at the target location pointing to an arbitrary system path; when CodeMeter (running as SYSTEM) writes to the junction, files at the target location are overwritten or deleted. The attack requires local file system access but no special privileges. Patches are available in versions 8.41a and 9.10 and later.

Affected products

  • Wibu-Systems CodeMeter Runtime 8.40 to 8.41a (excluding), 9.00 to 9.10 (excluding)

Timeline

  • 2026-08-27: disclosed

References

Related threats