CVE-2026-81576
EUVD-2026-6698327.08.2026, 10:16
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| wibu | codemeter_runtime | 9.0 ≤ 𝑥 < 9.10 | CNA |
| wibu | codemeter_runtime | 8.0 ≤ 𝑥 < 8.41a | CNA |
| wibu | codemeter_runtime | 7.0 | CNA |
| wibu | codemeter_runtime | 6.0 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure