HIGHVulnerability

CVE-2026-81573

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

Properties

severity
HIGH
score
8.6
epss_score
0.00456
cve_id
CVE-2026-81573
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
published_at
2026-08-27T10:16:39.943
last_modified
2026-09-01T20:56:59.203
epss_percentile
0.38102

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81573 — Ninja Signal Threat Intelligence | Ninja Signal