origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. | |
| Title | Improper Access Control in Local-Only Configuration Commands | |
| First Time appeared |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.x:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.x:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: wibu
Published:
Updated: 2026-08-27T13:33:47.763Z
Reserved: 2026-08-27T07:01:24.780Z
Link: CVE-2026-81573
Updated: 2026-08-27T13:33:42.038Z
Status : Received
Published: 2026-08-27T10:16:39.943
Modified: 2026-08-27T17:20:54.857
Link: CVE-2026-81573
No data.
OpenCVE Enrichment
Updated: 2026-08-27T13:00:11Z