Description
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read
license information belonging to another handle.
Published: 2026-08-27
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is triggered when CodeMeter Runtime is used in server mode. Early builds before 8.41a and 9.10 use a weak cryptographic SID as the only authentication token for a session. An attacker can brute‑force this SID, obtain another user's session handle, and read the license data stored in that handle. The result is unauthorized disclosure of proprietary license information and a confidentiality breach that could aid further attacks.

Affected Systems

Affected is Wibu Systems AG CodeMeter Runtime. Any installation of the runtime before version 8.41a or before 9.10 that is configured as a server is vulnerable. Versions 6.x, 7.x, 8.x up to 8.40, and 9.x up to 9.09 match the CPE entries and are therefore within scope.

Risk and Exploitability

The CVSS score of 7.7 marks the flaw as high severity. Although EPSS data is missing and the vulnerability is not yet in the CISA KEV catalog, the weakness can be exploited by anyone who can reach the server interface. The attacker simply needs to find the SID field, perform a brute‑force search, and once a valid SID is found, the corresponding session handle reveals the license data. The lack of additional privilege requirements and the straightforward attack path make it a significant risk for exposed CodeMeter Runtime servers.

Generated by OpenCVE AI on August 27, 2026 at 10:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CodeMeter Runtime to version 8.41a or later, or 9.10 or later, where the session authentication has been strengthened.
  • If server mode is not required, disable or remove the server configuration to eliminate the attack surface.
  • Restrict network access to the runtime by using firewall rules or network segmentation so only trusted hosts can reach the server interface.
  • Monitor license server logs for repeated authentication failures that may indicate brute‑force attempts.

Generated by OpenCVE AI on August 27, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.
Title Improper Authentication of Session Handles
First Time appeared Wibu-systems-ag
Wibu-systems-ag codemeter-runtime
Weaknesses CWE-639
CPEs cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:*
cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.00:*:*:*:*:*:*:*
cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.00:*:*:*:*:*:*:*
Vendors & Products Wibu-systems-ag
Wibu-systems-ag codemeter-runtime
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Wibu-systems-ag Codemeter-runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: wibu

Published:

Updated: 2026-08-27T08:00:26.426Z

Reserved: 2026-08-27T07:01:24.780Z

Link: CVE-2026-81576

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:40.313

Modified: 2026-08-27T10:16:40.313

Link: CVE-2026-81576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T10:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key