Vulnerability Description
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-81573?
CVE-2026-81573 is a vulnerability with a CVSS score of 8.6 (HIGH). If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network c...
How severe is CVE-2026-81573?
CVE-2026-81573 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81573?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.