If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. | |
| Title | Improper Access Control in Local-Only Configuration Commands | |
| First Time appeared |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.x:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.x:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: wibu
Published:
Updated: 2026-08-27T07:56:22.618Z
Reserved: 2026-08-27T07:01:24.780Z
Link: CVE-2026-81573
No data.
Status : Received
Published: 2026-08-27T10:16:39.943
Modified: 2026-08-27T10:16:39.943
Link: CVE-2026-81573
No data.
OpenCVE Enrichment
Updated: 2026-08-27T10:45:17Z
Weaknesses