CVE-2026-81572
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.
Published:Aug 27, 2026
Last Modified:Sep 4, 2026
EPS:Aug 27, 2026
EPSS Score:0.00166
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Wibu-systems-ag
Product
Codemeter-runtime
Wibu-systems-ag
Codemeter-runtime
Vendor
Wibusys
Product
Codemeter Runtime Kit
Wibusys
Codemeter Runtime Kit
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
