HIGHVulnerability

CVE-2026-81576

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

Properties

severity
HIGH
score
7.7
epss_score
0.00326
cve_id
CVE-2026-81576
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
published_at
2026-08-27T10:16:40.313
last_modified
2026-09-01T20:56:59.203
epss_percentile
0.25281

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81576 — Ninja Signal Threat Intelligence | Ninja Signal