Vulnerability Description
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-81576?
CVE-2026-81576 is a vulnerability with a CVSS score of 7.7 (HIGH). If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force ...
How severe is CVE-2026-81576?
CVE-2026-81576 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81576?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.