{"id":"CVE-2026-81572","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-81572","summary":"In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\\CM-Stick. The directory…","details":"In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\\CM-Stick. The directory and\nfile paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file\noperations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary\nsystem path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted\nwith System privileges and potentially enable local privilege escalation.","published":"2026-08-27T10:16:39.810","modified":"2026-08-28T08:16:58.317","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-103081.pdf"},{"type":"WEB","url":"https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T08:16:58.317"}}