如果 CodeMeter Runtime 版本低于 8.41a 或 9.10 且被配置为服务器,其配置命令处理器未强制实施基于网络来源的限制。因此,原本仅针对本地或同网络客户端设计的命令,可被任意远程对等节点执行。攻击者由此可以读取潜在的敏感配置数据,并覆盖 中的选定值。这包括对 CodeMeter WebAdmin 凭据哈希值的访问,从而可能导致 WebAdmin 被接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wibu-systems-ag | codemeter-runtime | 9.00 ~ 9.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81581 | 8.8 HIGH | User input in WibuKey is used (without proper sanitization) to compute the address of a po |
| CVE-2026-81579 | 8.8 HIGH | An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivilege |
| CVE-2026-81574 | 8.2 HIGH | Format String Vulnerability in Logger |
| CVE-2026-81572 | 7.8 HIGH | Local Privilege Escalation in CodeMeter Runtime on Windows |
| CVE-2026-81576 | 7.7 HIGH | Improper Authentication of Session Handles |
| CVE-2026-81575 | 7.5 HIGH | Missing Sanity Checks for Buffer Lengths |
No comments yet