CVE-2026-81576
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak<br />
SID as sole authenticator. An attacker can brute-force the SID, recover another session&#39;s handle number, and read<br />
license information belonging to another handle.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH



