Junglewise Threat Intelligence

CVE-2026-81573: Wibu-Systems CodeMeter Runtime network-origin bypass in configuration handler

CVE-2026-81573 · Severity: high · CVSS 8.6 · Published 2026-08-27

Technologies: Wibu-Systems CodeMeter Runtime. Vendors: Wibu-Systems.

Executive brief

CodeMeter Runtime is license management software deployed on computers to enable protected applications. When configured as a server, it accepts configuration commands without properly validating that they originate from authorized local or same-network clients. An attacker on the internet can send crafted commands to read sensitive configuration data, modify server settings, and crucially, obtain or reset credentials for the CodeMeter WebAdmin interface—enabling complete administrative takeover of the licensing system.

Technical details

The vulnerability is a network-origin validation bypass in the configuration command handler of CodeMeter Runtime when operating in server mode. The affected component fails to enforce network-origin restrictions on configuration commands, allowing arbitrary remote peers to execute operations intended only for local or trusted network clients. An attacker can read potentially sensitive configuration data stored in Server.ini, overwrite selected configuration values, and extract or modify the hash of WebAdmin credentials. This requires network access to the CodeMeter Runtime service port but does not require prior authentication or user interaction. The vulnerability affects versions before 8.41a and 9.10; fixes are available in those versions and later.

Affected products

  • Wibu-Systems CodeMeter Runtime before 8.41a and before 9.10

Timeline

  • 2026-08-27: disclosed

References

Related threats