CVE-2026-81575CWE-130

CVE-2026-81575

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
36.9
In the wild
Unconfirmed
What it is

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and

the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a

segmentation fault that ultimately crashes the CodeMeter Runtime.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00441 · 36.9th percentile
Weakness
CWE-130 · Improper Handling of Length Parameter Inconsistency
Published
2026-08-27T14:16Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:54Z
    EPSS moved — → 0%
    epss
  • 27 AUG 07:13Z
    Missing Sanity Checks for Buffer Lengths
    cvelistv5