CVE-2026-81573
8.6Wibu-Systems · CodeMeter Runtime
CodeMeter Runtime fails to enforce network origin restrictions for configuration commands, allowing unauthenticated remote attackers to read sensitive data and overwrite the Server.ini configuration.
Executive summary
A critical access control vulnerability in Wibu-Systems CodeMeter Runtime allows unauthenticated remote attackers to take over WebAdmin by manipulating configuration files.
Vulnerability
This vulnerability is an improper access control flaw where the configuration command handler fails to restrict requests to local or same-network clients. An unauthenticated attacker can send commands to the server to read or modify the Server.ini file, including sensitive credential hashes.
Business impact
The ability for an unauthenticated remote attacker to modify the Server.ini file and retrieve credential hashes poses a severe risk of full administrative takeover of the CodeMeter WebAdmin interface. With a CVSS score of 8.6, this vulnerability represents a high risk to business operations, as it can lead to unauthorized system configuration changes, potential service disruption, and compromise of license management infrastructure.
Remediation
Immediate Action: Update Wibu-Systems CodeMeter Runtime to version 8.41a, 9.10, or later versions as specified in the official vendor advisory.
Proactive Monitoring: Review system logs for unusual configuration change requests or unexpected access to the WebAdmin interface from external network segments.
Compensating Controls: Implement network-level access control lists (ACLs) or firewall rules to restrict access to the CodeMeter communication ports to authorized administrative IP addresses only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the ease of exploitability and the high potential for administrative compromise, organizations using CodeMeter Runtime as a server should prioritize applying the security updates immediately. Ensure that all instances of the software are identified across the environment to prevent leaving vulnerable endpoints exposed to remote command execution.
More Wibu-Systems CVEs
Sources
Originally found and disclosed by Andrew Teylu of Vector Informatik GmbH, per the CVE Program record.