{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "Several vulnerabilities in the Wibu Systems CodeMeter Runtime affect the SICK products Sentio Creator, Sentio Compose, Safety Designer, Stream Editor, PLB and multiple SICK Industrial PCs (APU0G00, APU0G50, APU0G03, APU3F00, APU4600, APU8G00 and APU8G20), which ship with CodeMeter Runtime as part of their preinstalled image. For Sentio Compose, Safety Designer, Stream Editor and PLB, only CVE-2026-81572 is relevant. Vulnerabilities requiring the CodeMeter Runtime to be configured as a server are not applicable to default Sentio Compose, Safety Designer, Stream Editor and PLB installations, as the runtime is shipped with the Network Server and CmWAN Server functionalities disabled. Customers who have modified the default configuration and enabled CodeMeter server functionality should review the remaining vulnerabilities for potential impact. The vulnerabilities could potentially affect the integrity, confidentiality, and availability of the affected products.",
        "title": "summary"
      },
      {
        "category": "general",
        "text": "As general security measures, SICK recommends minimizing network exposure of the devices, restricting network access and following recommended security practices in order to run the devices in a protected IT environment.",
        "title": "General Security Measures"
      },
      {
        "category": "general",
        "text": "SICK performs vulnerability classification by using the CVSS scoring system (*CVSS v3.1*). The environmental score is dependent on the customer’s environment and can affect the overall CVSS score. SICK recommends that customers individually evaluate the environmental score to achieve final scoring.",
        "title": "Vulnerability Classification"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "psirt@sick.de",
      "issuing_authority": "SICK AG issues and issues in EHS products (when related to the Endress+Hauser SICK (EHS) joint venture).",
      "name": "SICK PSIRT",
      "namespace": "https://www.sick.com/psirt"
    },
    "references": [
      {
        "summary": "SICK PSIRT Security Advisories",
        "url": "https://www.sick.com/psirt"
      },
      {
        "summary": "SICK Operating Guidelines",
        "url": "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf"
      },
      {
        "summary": "ICS-CERT recommended practices on Industrial Security",
        "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
      },
      {
        "summary": "CVSS v3.1 Calculator",
        "url": "https://www.first.org/cvss/calculator/3.1"
      },
      {
        "category": "self",
        "summary": "The canonical URL.",
        "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0011.json"
      },
      {
        "summary": "WIBU-SYSTEMS Security Advisory for CVE-2026-81572",
        "url": "https://www.wibu.com/support/security-advisories/wibu-103081.html"
      },
      {
        "summary": "WIBU-SYSTEMS Security Advisory for CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576",
        "url": "https://www.wibu.com/support/security-advisories/wibu-103401.html"
      }
    ],
    "title": "Vulnerabilities in Wibu Systems CodeMeter Runtime Affect Multiple SICK Products",
    "tracking": {
      "current_release_date": "2026-09-04T13:00:00.000Z",
      "generator": {
        "date": "2026-09-04T08:31:49.549Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.11"
        }
      },
      "id": "sca-2026-0011",
      "initial_release_date": "2026-09-04T13:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-04T13:00:00.000Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK Sentio Creator all versions",
                      "product_id": "CSAFPID-51000"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Sentio Creator"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "< 2.1.0",
                    "product": {
                      "name": "SICK Sentio Compose < 2.1.0",
                      "product_id": "CSAFPID-51004"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "2.1.0",
                    "product": {
                      "name": "SICK Sentio Compose 2.1.0",
                      "product_id": "CSAFPID-51005"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Sentio Compose"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK Stream Editor all versions",
                      "product_id": "CSAFPID-51002"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Stream Editor"
              }
            ],
            "category": "product_family",
            "name": "Engineering Tools"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": ">= SD2025.03 V1.20.2141",
                    "product": {
                      "name": "SICK Safety Designer >= SD2025.03 V1.20.2141",
                      "product_id": "CSAFPID-51001"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Safety Designer"
              }
            ],
            "category": "product_family",
            "name": "Safety controllers"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK PLB all versions",
                      "product_id": "CSAFPID-11007"
                    }
                  }
                ],
                "category": "product_name",
                "name": "PLB"
              }
            ],
            "category": "product_family",
            "name": "Robot guidance systems"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU0G00 all versions",
                      "product_id": "CSAFPID-11000"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU0G00"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU0G50 all versions",
                      "product_id": "CSAFPID-11001"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU0G50"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU0G03 all versions",
                      "product_id": "CSAFPID-11002"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU0G03"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU3F00 all versions",
                      "product_id": "CSAFPID-11003"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU3F00"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU4600 all versions",
                      "product_id": "CSAFPID-11004"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU4600"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU8G00 all versions",
                      "product_id": "CSAFPID-11005"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU8G00"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "SICK APU8G20 all versions",
                      "product_id": "CSAFPID-11006"
                    }
                  }
                ],
                "category": "product_name",
                "name": "APU8G20"
              }
            ],
            "category": "product_family",
            "name": "Industrial PCs"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.7 (Image ID 30)",
                "product": {
                  "name": "SICK APU0G00 firmware Image Version 1.0.0.7 Image ID 30",
                  "product_id": "CSAFPID-21000",
                  "product_identification_helper": {
                    "skus": [
                      "1145482",
                      "1144594",
                      "1144593"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 38)",
                "product": {
                  "name": "SICK APU0G00 firmware Image Version 1.0.0.2 Image ID 38",
                  "product_id": "CSAFPID-21001",
                  "product_identification_helper": {
                    "skus": [
                      "1145482",
                      "1144594",
                      "1144593",
                      "1158608",
                      "1157081"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU0G00 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 38)",
                "product": {
                  "name": "SICK APU0G50 firmware Image Version 1.0.0.2 Image ID 38",
                  "product_id": "CSAFPID-21002",
                  "product_identification_helper": {
                    "skus": [
                      "1145482",
                      "1144594",
                      "1144593",
                      "1158608",
                      "1157081"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.1 (Image ID 45)",
                "product": {
                  "name": "SICK APU0G50 firmware Image Version 1.0.0.1 Image ID 45",
                  "product_id": "CSAFPID-21003",
                  "product_identification_helper": {
                    "skus": [
                      "1155820"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU0G50 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.1 (Image ID 41)",
                "product": {
                  "name": "SICK APU0G03 firmware Image Version 1.0.0.1 Image ID 41",
                  "product_id": "CSAFPID-21004",
                  "product_identification_helper": {
                    "skus": [
                      "1153518"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 36)",
                "product": {
                  "name": "SICK APU0G03 firmware Image Version 1.0.0.2 Image ID 36",
                  "product_id": "CSAFPID-21005",
                  "product_identification_helper": {
                    "skus": [
                      "1142465"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU0G03 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.0 (Image ID 27)",
                "product": {
                  "name": "SICK APU3F00 firmware Image Version 1.0.0.0 Image ID 27",
                  "product_id": "CSAFPID-21006",
                  "product_identification_helper": {
                    "skus": [
                      "1140440"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.0 (Image ID 46)",
                "product": {
                  "name": "SICK APU3F00 firmware Image Version 1.0.0.0 Image ID 46",
                  "product_id": "CSAFPID-21007",
                  "product_identification_helper": {
                    "skus": [
                      "1142365"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU3F00 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.1.0.1 (Image ID 18)",
                "product": {
                  "name": "SICK APU4600 firmware Image Version 1.1.0.1 Image ID 18",
                  "product_id": "CSAFPID-21008",
                  "product_identification_helper": {
                    "skus": [
                      "1125534",
                      "1144859"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU4600 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.11 (Image ID 15)",
                "product": {
                  "name": "SICK APU8G00 firmware Image Version 1.0.0.11 Image ID 15",
                  "product_id": "CSAFPID-21009",
                  "product_identification_helper": {
                    "skus": [
                      "1140442"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 44)",
                "product": {
                  "name": "SICK APU8G00 firmware Image Version 1.0.0.2 Image ID 44",
                  "product_id": "CSAFPID-21010",
                  "product_identification_helper": {
                    "skus": [
                      "1154211"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU8G00 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 29)",
                "product": {
                  "name": "SICK APU8G20 firmware Image Version 1.0.0.2 Image ID 29",
                  "product_id": "CSAFPID-21011",
                  "product_identification_helper": {
                    "skus": [
                      "1144083"
                    ]
                  }
                }
              },
              {
                "category": "product_version",
                "name": "1.0.0.2 (Image ID 32)",
                "product": {
                  "name": "SICK APU8G20 firmware Image Version 1.0.0.2 Image ID 32",
                  "product_id": "CSAFPID-21012",
                  "product_identification_helper": {
                    "skus": [
                      "1149272"
                    ]
                  }
                }
              }
            ],
            "category": "product_name",
            "name": "APU8G20 firmware"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "SICK PLB firmware all versions",
                  "product_id": "CSAFPID-21013"
                }
              }
            ],
            "category": "product_name",
            "name": "PLB firmware"
          }
        ],
        "category": "vendor",
        "name": "SICK AG"
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G00 with Image Version 1.0.0.7 and Image ID 30",
          "product_id": "CSAFPID-31000"
        },
        "product_reference": "CSAFPID-21000",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G00 with Image Version 1.0.0.2 and Image ID 38",
          "product_id": "CSAFPID-31001"
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G50 with Image Version 1.0.0.2 and Image ID 38",
          "product_id": "CSAFPID-31002"
        },
        "product_reference": "CSAFPID-21002",
        "relates_to_product_reference": "CSAFPID-11001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G50 with Image Version 1.0.0.1 and Image ID 45",
          "product_id": "CSAFPID-31003"
        },
        "product_reference": "CSAFPID-21003",
        "relates_to_product_reference": "CSAFPID-11001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G03 with Image Version 1.0.0.1 and Image ID 41",
          "product_id": "CSAFPID-31004"
        },
        "product_reference": "CSAFPID-21004",
        "relates_to_product_reference": "CSAFPID-11002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU0G03 with Image Version 1.0.0.2 and Image ID 36",
          "product_id": "CSAFPID-31005"
        },
        "product_reference": "CSAFPID-21005",
        "relates_to_product_reference": "CSAFPID-11002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU3F00 with Image Version 1.0.0.0 and Image ID 27",
          "product_id": "CSAFPID-31006"
        },
        "product_reference": "CSAFPID-21006",
        "relates_to_product_reference": "CSAFPID-11003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU3F00 with Image Version 1.0.0.0 and Image ID 46",
          "product_id": "CSAFPID-31007"
        },
        "product_reference": "CSAFPID-21007",
        "relates_to_product_reference": "CSAFPID-11003"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU4600 with Image Version 1.1.0.1 and Image ID 18",
          "product_id": "CSAFPID-31008"
        },
        "product_reference": "CSAFPID-21008",
        "relates_to_product_reference": "CSAFPID-11004"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU8G00 with Image Version 1.0.0.11 and Image ID 15",
          "product_id": "CSAFPID-31009"
        },
        "product_reference": "CSAFPID-21009",
        "relates_to_product_reference": "CSAFPID-11005"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU8G00 with Image Version 1.0.0.2 and Image ID 44",
          "product_id": "CSAFPID-31010"
        },
        "product_reference": "CSAFPID-21010",
        "relates_to_product_reference": "CSAFPID-11005"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU8G20 with Image Version 1.0.0.2 and Image ID 29",
          "product_id": "CSAFPID-31011"
        },
        "product_reference": "CSAFPID-21011",
        "relates_to_product_reference": "CSAFPID-11006"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK APU8G20 with Image Version 1.0.0.2 and Image ID 32",
          "product_id": "CSAFPID-31012"
        },
        "product_reference": "CSAFPID-21012",
        "relates_to_product_reference": "CSAFPID-11006"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "SICK PLB with all firmware versions",
          "product_id": "CSAFPID-31013"
        },
        "product_reference": "CSAFPID-21013",
        "relates_to_product_reference": "CSAFPID-11007"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-81572",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "audience": "all",
          "category": "summary",
          "text": "cmu.exe --create-io --file C: creates a predictable temporary file under C:\\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-51005"
        ],
        "known_affected": [
          "CSAFPID-51000",
          "CSAFPID-51001",
          "CSAFPID-51002",
          "CSAFPID-51004",
          "CSAFPID-31000",
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012",
          "CSAFPID-31013"
        ],
        "recommended": [
          "CSAFPID-51005"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-27T14:54:07.531Z",
          "details": "Customers are strongy recommended to update the Codemeter Runtime to the latest version (>= 9.10).\r\nThe software can be downloaded directly on the Wibu Systems website: https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html",
          "product_ids": [
            "CSAFPID-51000",
            "CSAFPID-51001",
            "CSAFPID-51002",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-08-26T00:00:00.000Z",
          "details": "Users are recommended to upgrade to version 2.1.0.",
          "product_ids": [
            "CSAFPID-51004"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51000",
            "CSAFPID-51001",
            "CSAFPID-51002",
            "CSAFPID-51004",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012",
            "CSAFPID-31013"
          ]
        }
      ],
      "title": "CVE-2026-81572"
    },
    {
      "cve": "CVE-2026-81573",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "audience": "all",
          "category": "summary",
          "text": "If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-51000",
          "CSAFPID-31000",
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-27T14:54:07.531Z",
          "details": "Customers are strongy recommended to update the Codemeter Runtime to the latest version (>= 9.10).\r\nThe software can be downloaded directly on the Wibu Systems website: https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html",
          "product_ids": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 8.6,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.6,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "title": "CVE-2026-81573"
    },
    {
      "cve": "CVE-2026-81574",
      "cwe": {
        "id": "CWE-134",
        "name": "Use of Externally-Controlled Format String"
      },
      "notes": [
        {
          "audience": "all",
          "category": "summary",
          "text": "The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-51000",
          "CSAFPID-31000",
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-27T14:54:07.531Z",
          "details": "Customers are strongy recommended to update the Codemeter Runtime to the latest version (>= 9.10).\r\nThe software can be downloaded directly on the Wibu Systems website: https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html",
          "product_ids": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 8.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "title": "CVE-2026-81574"
    },
    {
      "cve": "CVE-2026-81575",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "audience": "all",
          "category": "summary",
          "text": "If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-51000",
          "CSAFPID-31000",
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-27T14:54:07.532Z",
          "details": "Customers are strongy recommended to update the Codemeter Runtime to the latest version (>= 9.10).\r\nThe software can be downloaded directly on the Wibu Systems website: https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html",
          "product_ids": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 8.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "title": "CVE-2026-81575"
    },
    {
      "cve": "CVE-2026-81576",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "notes": [
        {
          "audience": "all",
          "category": "summary",
          "text": "If configured as a server, CodeMeter Runtime issues handles per connection and relies on a cryptographically SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.",
          "title": "Summary"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-51000",
          "CSAFPID-31000",
          "CSAFPID-31001",
          "CSAFPID-31002",
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005",
          "CSAFPID-31006",
          "CSAFPID-31007",
          "CSAFPID-31008",
          "CSAFPID-31009",
          "CSAFPID-31010",
          "CSAFPID-31011",
          "CSAFPID-31012"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-27T14:54:07.532Z",
          "details": "Customers are strongy recommended to update the Codemeter Runtime to the latest version (>= 9.10).\r\nThe software can be downloaded directly on the Wibu Systems website: https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html",
          "product_ids": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.7,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 7.7,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-51000",
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002",
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005",
            "CSAFPID-31006",
            "CSAFPID-31007",
            "CSAFPID-31008",
            "CSAFPID-31009",
            "CSAFPID-31010",
            "CSAFPID-31011",
            "CSAFPID-31012"
          ]
        }
      ],
      "title": "CVE-2026-81576"
    }
  ]
}