Executive brief
CodeMeter Runtime is a software licensing and protection service that runs on Windows, Linux, and macOS systems to manage software licenses and protect applications. A format string vulnerability in the logging component allows attackers to crash the service or leak sensitive memory contents such as stack canaries and process memory. Exploitation can occur locally via command-line tools or remotely when combined with another vulnerability, potentially compromising the integrity of protected applications and exposing confidential data.
Technical details
The vulnerability is a format string injection flaw in CodeMeter Runtime's logger that fails to sanitize input strings in certain cases. Attackers can inject printf-style format specifiers to read or write memory. The attack vector includes local exploitation via the cmu --set-proxy command to set the proxy value, and remote exploitation when combined with CVE-2026-81573 by manipulating the General.ProxyServer setting. Successful exploitation allows denial of service (crash) or information disclosure (process memory and stack canaries). The vulnerability affects versions before 8.41a and 9.10; patches are available in those versions.
Affected products
- Wibu-Systems CodeMeter Runtime before 8.41a and before 9.10
Timeline
- 2026-08-27: disclosed
- 2026-08-27: advisory: CVE-2026-81574 published