{"api_version":"1","generated_at":"2026-08-27T13:37:53+00:00","cve":"CVE-2026-81573","urls":{"html":"https://cve.report/CVE-2026-81573","api":"https://cve.report/api/cve/CVE-2026-81573.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-81573","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-81573"},"summary":{"title":"Improper Access Control in Local-Only Configuration Commands","description":"If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-\norigin restrictions. Commands intended only for local or same-network clients can therefore be executed by\narbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values\nin Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin\ntakeover.","state":"PUBLISHED","assigner":"wibu","published_at":"2026-08-27 10:16:39","updated_at":"2026-08-27 10:16:39"},"problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"2fc02b1f-71e7-4514-a878-169626f68903","type":"Secondary","score":"8.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103401.pdf","name":"https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103401.pdf","refsource":"2fc02b1f-71e7-4514-a878-169626f68903","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81573","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81573","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"wibu-systems-ag","product":"codemeter-runtime","version":"affected 9.00 9.10 custom","platforms":[]},{"source":"CNA","vendor":"wibu-systems-ag","product":"codemeter-runtime","version":"affected 8.00 8.41a custom","platforms":[]},{"source":"CNA","vendor":"wibu-systems-ag","product":"codemeter-runtime","version":"affected 7.x","platforms":[]},{"source":"CNA","vendor":"wibu-systems-ag","product":"codemeter-runtime","version":"affected 6.x","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Andrew Teylu of Vector Informatik GmbH","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://www.wibu.com/products/codemeter/runtime.html","defaultStatus":"unaffected","product":"codemeter-runtime","vendor":"wibu-systems-ag","versions":[{"lessThan":"9.10","status":"affected","version":"9.00","versionType":"custom"},{"lessThan":"8.41a","status":"affected","version":"8.00","versionType":"custom"},{"status":"affected","version":"7.x"},{"status":"affected","version":"6.x"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:*","versionEndExcluding":"9.10","versionStartIncluding":"9.00","vulnerable":true},{"criteria":"cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:*","versionEndExcluding":"8.41a","versionStartIncluding":"8.00","vulnerable":true},{"criteria":"cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.x:*:*:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.x:*:*:*:*:*:*:*","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Andrew Teylu of Vector Informatik GmbH"}],"datePublic":"2026-08-25T13:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-<br>origin restrictions. Commands intended only for local or same-network clients can therefore be executed by<br>arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values<br>in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin<br>takeover."}],"value":"If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-\norigin restrictions. Commands intended only for local or same-network clients can therefore be executed by\narbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values\nin Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin\ntakeover."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-27T07:56:22.618Z","orgId":"2fc02b1f-71e7-4514-a878-169626f68903","shortName":"wibu"},"references":[{"tags":["vendor-advisory"],"url":"https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103401.pdf"}],"source":{"discovery":"EXTERNAL"},"title":"Improper Access Control in Local-Only Configuration Commands","x_generator":{"engine":"Vulnogram 1.0.0-beta"}}},"cveMetadata":{"assignerOrgId":"2fc02b1f-71e7-4514-a878-169626f68903","assignerShortName":"wibu","cveId":"CVE-2026-81573","datePublished":"2026-08-27T07:09:09.122Z","dateReserved":"2026-08-27T07:01:24.780Z","dateUpdated":"2026-08-27T07:56:22.618Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-27 10:16:39","lastModifiedDate":"2026-08-27 10:16:39","problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"2fc02b1f-71e7-4514-a878-169626f68903","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"81573","Ordinal":"1","Title":"Improper Access Control in Local-Only Configuration Commands","CVE":"CVE-2026-81573","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"81573","Ordinal":"1","NoteData":"If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-\norigin restrictions. Commands intended only for local or same-network clients can therefore be executed by\narbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values\nin Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin\ntakeover.","Type":"Description","Title":"Improper Access Control in Local-Only Configuration Commands"}]}}}