IM
IronMonkey Threat Research

CVE-2026-81574 HIGH

Published: 2026-08-27 | Last Modified: 2026-09-01 | Status: Awaiting Analysis

Description

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.

CVSS Metrics

Base Score: 8.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactHIGH

Source: 2fc02b1f-71e7-4514-a878-169626f68903

Type: Secondary

Exploitability Score: 3.9

Impact Score: 4.2

Weaknesses

Source Type Description
2fc02b1f-71e7-4514-a878-169626f68903 Secondary
en CWE-134
Notification
Message here