PatchSiren cyber security CVE debrief
CVE-2026-81572 wibu-systems-ag CVE debrief
The CodeMeter Runtime, specifically versions 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, contains a local privilege escalation vulnerability. This issue arises from the creation of a predictable temporary file under C:CM-Stick, where directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can exploit this by creating a junction at the temporary file that points to an arbitrary system path. Given that CodeMeter Runtime operates with System privileges, this could allow for the deletion of arbitrary files with System privileges and potentially enable local privilege escalation. The vulnerability is particularly concerning due to its potential for impact with high CVSS score of 7.8. System administrators and security teams responsible for CodeMeter Runtime installations should review and apply patches to prevent potential local privilege escalation attacks. IT operations teams and vulnerability management teams should also be aware of the potential impact on their environments and prioritize patching accordingly. Additionally, security teams should monitor system file integrity and review logs for suspicious activity related to CodeMeter Runtime operations.
- Vendor
- wibu-systems-ag
- Product
- codemeter-runtime
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-01
Who should care
System administrators and security teams responsible for CodeMeter Runtime installations, particularly those using versions 8.40 to 9.00, should review and apply patches to prevent potential local privilege escalation attacks. IT operations teams and vulnerability management teams should also be aware of the potential impact on their environments and prioritize patching accordingly. Additionally, security teams should monitor system file integrity and review logs for suspicious activity related to CodeMeter Runtime operations.
Technical summary
The CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10 creates a predictable temporary file under C:CM-Stick. A local attacker can create a junction at the temporary file that points to an arbitrary system path, potentially enabling local privilege escalation. This vulnerability is particularly concerning due to CodeMeter Runtime's operation with System privileges, which could allow for arbitrary file deletion and potential elevation of privileges.
Defensive priority
CodeMeter Runtime local privilege escalation vulnerability requires immediate attention due to high CVSS score of 7.8.
Recommended defensive actions
- Review and apply vendor patches for CodeMeter Runtime versions 8.40 to 9.00
- Conduct inventory checks for affected CodeMeter Runtime versions
- Implement compensating controls to monitor and restrict access to sensitive areas
- Verify system file integrity and monitor for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page supports local privilege escalation vulnerability in CodeMeter Runtime. Limited information available on affected scope and vendor remediation. Further review of vendor documentation and system file integrity monitoring is recommended to validate system exposure and patch applicability. CodeMeter Runtime's temporary file creation and junction point handling require defensive scrutiny.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81572 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81572
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81572 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81572
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103081.pdf
2fc02b1f-71e7-4514-a878-169626f68903
-
Source reference
Unverified legacy reference
URL: https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application
2fc02b1f-71e7-4514-a878-169626f68903
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.