SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81576

HIGH · CVSS 7.7 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

CodeMeter Runtime versions prior to 8.41a and 9.10 are vulnerable due to the use of a cryptographically weak session identifier (SID) for authentication, which allows attackers to brute-force the SID and access session handles. This could lead to unauthorized reading of license information from other sessions, posing a significant risk to data confidentiality. Organizations using CodeMeter Runtime in server configurations should prioritize patching to mitigate this vulnerability.

CVE
CVE-2026-81576
Severity
HIGH
CVSS
7.7
EPSS
0.33%

Original NVD Description

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.