CVE-2026-81574

8.2

Wibu-Systems AG · CodeMeter Runtime

CodeMeter Runtime is vulnerable to a format string injection flaw, allowing unauthenticated remote attackers to crash the service or disclose sensitive process memory and stack canaries.

Executive summary

A critical format string vulnerability in Wibu-Systems CodeMeter Runtime allows unauthenticated remote attackers to cause denial of service or disclose sensitive process memory.

Vulnerability

The application fails to sanitize input strings within its logging mechanism, which allows an unauthenticated attacker to inject printf-style format specifiers. This flaw can be triggered locally or remotely, particularly when combined with other vulnerabilities to influence proxy settings.

Business impact

The ability for an unauthenticated attacker to disclose process memory and stack canaries poses a significant risk to data confidentiality and system integrity. Furthermore, the capacity to reliably crash the service leads to operational downtime, impacting business continuity. With a CVSS score of 8.2, this high-severity vulnerability requires immediate attention to prevent unauthorized information disclosure and service disruption.

Remediation

Immediate Action: Update CodeMeter Runtime to version 8.41a or 9.10 immediately to apply the necessary input sanitization patches.

Proactive Monitoring: Monitor service logs for unusual input patterns and review system logs for recurring crashes or unauthorized access attempts related to the proxy configuration.

Compensating Controls: Implement network-level restrictions to limit access to the CodeMeter service to trusted IP addresses only, and utilize a Web Application Firewall or similar inspection tool to block malicious format string payloads.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized memory disclosure and remote service disruption, this vulnerability presents a high risk to production environments. Security teams should prioritize updating the CodeMeter Runtime to the specified fixed versions immediately to remediate the underlying format string flaw and eliminate the attack vector.

More Wibu-Systems AG CVEs

Sources

Originally found and disclosed by Andrew Teylu of Vector Informatik GmbH, per the CVE Program record.