CVE-2026-81574
8.2Wibu-Systems AG · CodeMeter Runtime
CodeMeter Runtime is vulnerable to a format string injection flaw, allowing unauthenticated remote attackers to crash the service or disclose sensitive process memory and stack canaries.
Executive summary
A critical format string vulnerability in Wibu-Systems CodeMeter Runtime allows unauthenticated remote attackers to cause denial of service or disclose sensitive process memory.
Vulnerability
The application fails to sanitize input strings within its logging mechanism, which allows an unauthenticated attacker to inject printf-style format specifiers. This flaw can be triggered locally or remotely, particularly when combined with other vulnerabilities to influence proxy settings.
Business impact
The ability for an unauthenticated attacker to disclose process memory and stack canaries poses a significant risk to data confidentiality and system integrity. Furthermore, the capacity to reliably crash the service leads to operational downtime, impacting business continuity. With a CVSS score of 8.2, this high-severity vulnerability requires immediate attention to prevent unauthorized information disclosure and service disruption.
Remediation
Immediate Action: Update CodeMeter Runtime to version 8.41a or 9.10 immediately to apply the necessary input sanitization patches.
Proactive Monitoring: Monitor service logs for unusual input patterns and review system logs for recurring crashes or unauthorized access attempts related to the proxy configuration.
Compensating Controls: Implement network-level restrictions to limit access to the CodeMeter service to trusted IP addresses only, and utilize a Web Application Firewall or similar inspection tool to block malicious format string payloads.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized memory disclosure and remote service disruption, this vulnerability presents a high risk to production environments. Security teams should prioritize updating the CodeMeter Runtime to the specified fixed versions immediately to remediate the underlying format string flaw and eliminate the attack vector.
More Wibu-Systems AG CVEs
Sources
Originally found and disclosed by Andrew Teylu of Vector Informatik GmbH, per the CVE Program record.