HIGHVulnerability

CVE-2026-81574

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.

Properties

severity
HIGH
score
8.2
epss_score
0.00408
cve_id
CVE-2026-81574
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
published_at
2026-08-27T10:16:40.077
last_modified
2026-09-01T20:56:59.203
epss_percentile
0.34102

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of Externally-Controlled Format String

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81574 — Ninja Signal Threat Intelligence | Ninja Signal