CVE-2026-81576 PUBLISHED

Improper Authentication of Session Handles

Assigner: wibu
Reserved: 27.08.2026 Published: 27.08.2026 Updated: 27.08.2026

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 7.7

Product Status

Vendor wibu-systems-ag
Product codemeter-runtime
Versions Default: unaffected
  • affected from 9.00 to 9.10 (excl.)
  • affected from 8.00 to 8.41a (excl.)
  • Version 7.00 is affected
  • Version 6.00 is affected

Credits

  • Andrew Teylu of Vector Informatik GmbH reporter

References

Problem Types

  • CWE-639 Authorization bypass through User-Controlled key CWE