CVE-2026-81575

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026

Description

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and<br /> the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a<br /> segmentation fault that ultimately crashes the CodeMeter Runtime.