PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81572 wibu-systems-ag CVE debrief

The CodeMeter Runtime, specifically versions 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, contains a local privilege escalation vulnerability. This issue arises from the creation of a predictable temporary file under C:CM-Stick, where directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can exploit this by creating a junction at the temporary file that points to an arbitrary system path. Given that CodeMeter Runtime operates with System privileges, this could allow for the deletion of arbitrary files with System privileges and potentially enable local privilege escalation. The vulnerability is particularly concerning due to its potential for impact with high CVSS score of 7.8. System administrators and security teams responsible for CodeMeter Runtime installations should review and apply patches to prevent potential local privilege escalation attacks. IT operations teams and vulnerability management teams should also be aware of the potential impact on their environments and prioritize patching accordingly. Additionally, security teams should monitor system file integrity and review logs for suspicious activity related to CodeMeter Runtime operations.

Vendor
wibu-systems-ag
Product
codemeter-runtime
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-01
Advisory published
2026-08-27
Advisory updated
2026-09-01

Who should care

System administrators and security teams responsible for CodeMeter Runtime installations, particularly those using versions 8.40 to 9.00, should review and apply patches to prevent potential local privilege escalation attacks. IT operations teams and vulnerability management teams should also be aware of the potential impact on their environments and prioritize patching accordingly. Additionally, security teams should monitor system file integrity and review logs for suspicious activity related to CodeMeter Runtime operations.

Technical summary

The CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10 creates a predictable temporary file under C:CM-Stick. A local attacker can create a junction at the temporary file that points to an arbitrary system path, potentially enabling local privilege escalation. This vulnerability is particularly concerning due to CodeMeter Runtime's operation with System privileges, which could allow for arbitrary file deletion and potential elevation of privileges.

Defensive priority

CodeMeter Runtime local privilege escalation vulnerability requires immediate attention due to high CVSS score of 7.8.

Recommended defensive actions

  • Review and apply vendor patches for CodeMeter Runtime versions 8.40 to 9.00
  • Conduct inventory checks for affected CodeMeter Runtime versions
  • Implement compensating controls to monitor and restrict access to sensitive areas
  • Verify system file integrity and monitor for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page supports local privilege escalation vulnerability in CodeMeter Runtime. Limited information available on affected scope and vendor remediation. Further review of vendor documentation and system file integrity monitoring is recommended to validate system exposure and patch applicability. CodeMeter Runtime's temporary file creation and junction point handling require defensive scrutiny.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81572 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81572

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81572 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81572

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103081.pdf

    2fc02b1f-71e7-4514-a878-169626f68903

  • Source reference

    Unverified legacy reference

    URL: https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application

    2fc02b1f-71e7-4514-a878-169626f68903

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.