If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read
license information belonging to another handle.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle. | |
| Title | Improper Authentication of Session Handles | |
| First Time appeared |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.00:*:*:*:*:*:*:* cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.00:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wibu-systems-ag
Wibu-systems-ag codemeter-runtime |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: wibu
Published: 2026-08-27T07:14:11.299Z
Updated: 2026-08-27T13:13:33.594Z
Reserved: 2026-08-27T07:01:24.780Z
Link: CVE-2026-81576
No data.
Status : Received
Published: 2026-08-27T10:16:40.313
Modified: 2026-08-27T10:16:40.313
Link: CVE-2026-81576
No data.