{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-81574", "assignerOrgId": "2fc02b1f-71e7-4514-a878-169626f68903", "state": "PUBLISHED", "assignerShortName": "wibu", "dateReserved": "2026-08-27T07:01:24.780Z", "datePublished": "2026-08-27T07:11:56.916Z", "dateUpdated": "2026-08-27T13:32:50.315Z" }, "containers": { "cna": { "affected": [ { "collectionURL": "https://www.wibu.com/products/codemeter/runtime.html", "defaultStatus": "unaffected", "product": "codemeter-runtime", "vendor": "wibu-systems-ag", "versions": [ { "lessThan": "9.10", "status": "affected", "version": "9.00", "versionType": "custom" }, { "lessThan": "8.41a", "status": "affected", "version": "8.00", "versionType": "custom" }, { "status": "affected", "version": "7.00" }, { "status": "unaffected", "version": "6.00" } ] } ], "cpeApplicability": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:*", "versionEndExcluding": "9.10", "versionStartIncluding": "9.00", "vulnerable": true }, { "criteria": "cpe:2.3:a:wibu-systems-ag:codemeter-runtime:*:*:*:*:*:*:*:*", "versionEndExcluding": "8.41a", "versionStartIncluding": "8.00", "vulnerable": true }, { "criteria": "cpe:2.3:a:wibu-systems-ag:codemeter-runtime:7.00:*:*:*:*:*:*:*", "vulnerable": true }, { "criteria": "cpe:2.3:a:wibu-systems-ag:codemeter-runtime:6.00:*:*:*:*:*:*:*", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "OR" } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Andrew Teylu of Vector Informatik GmbH" } ], "datePublic": "2026-08-25T13:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory
and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and
remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this
vulnerability." } ], "value": "In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format\nspecifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory\nand stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and\nremotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this\nvulnerability." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.2, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-134", "description": "CWE-134 Use of Externally-Controlled format string", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "orgId": "2fc02b1f-71e7-4514-a878-169626f68903", "shortName": "wibu", "dateUpdated": "2026-08-27T08:01:30.061Z" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103401.pdf" } ], "source": { "discovery": "EXTERNAL" }, "title": "Format String Vulnerability in Logger", "x_generator": { "engine": "Vulnogram 1.0.0-beta" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-27T13:32:09.372443Z", "id": "CVE-2026-81574", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-27T13:32:50.315Z" } } ] } }