CVE-2026-81576

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 10:16

Updated : 2026-09-01 20:56


NVD link : CVE-2026-81576

Mitre link : CVE-2026-81576

CVE.ORG link : CVE-2026-81576


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key