CVE-2026-81573
Wibu-Systems has patched multiple vulnerabilities in CodeMeter Runtime. The vulnerabilities are located in different components of CodeMeter Runtime, particularly in versions prior to 8.41a and 9.10. A local attacker can exploit improper verification of NTFS reparse points when creating temporary files by cmu.exe, which can lead to the deletion of arbitrary system files with System privileges and thus local privilege escalation. Additionally, the configuration command handler contains a flaw that prevents network restrictions from being correctly enforced, allowing a remote attacker to obtain unauthorized access to sensitive configuration data and control over the WebAdmin interface. Furthermore, there is an input sanitization issue in the logger module that allows format specifiers to be injected, which can lead to crashes and possible information leaks, both locally and remotely, especially in combination with CVE-2026-81573. There is also missing proper bounds checking on the data length in opcode 0x5e requests, which can cause a segmentation fault and affect the stability of the server component. Finally, a weak SID is used for authentication, allowing brute-force attacks to gain access to session handles and thus license information from other sessions.
CSIRTS triage
- What
- CodeMeter Runtime contains improper NTFS reparse point verification, network restriction bypass, and format string injection vulnerabilities allowing privilege escalation, unauthorized configuration access, and information disclosure.
- Who is affected
- Systems running CodeMeter Runtime versions prior to 8.41a and 9.10; local attackers can escalate to system privileges, remote attackers can access WebAdmin.
- Urgency
- High; local privilege escalation and remote configuration access vulnerabilities in privileged software.
- Action
- Update CodeMeter Runtime to version 8.41a or 9.10 or later addressing CVE-2026-81573.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-81573
Get an email if CVE-2026-81573 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-81573)