Back to overview

TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

VDE-2026-091
Last update
09/15/2026 09:00
Published at
09/15/2026 09:00
Vendor(s)
Trumpf SE + Co. KG
External ID
VDE-2026-091
CSAF Document

Summary

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

Impact

The affected CodeMeter Runtime on Windows version has several vulnerabilities.

  • CVE-2026-81572: Allows under certain circumstances deletion of arbitrary files with System Privileges and could potentially enable Escalation of Privileges for an unprivileged account.

  • CVE-2026-81573: Allows commands intended for local or same-network clients only to be executed by arbitrary network peers. An attacker can overwrite values in Server.ini, enabling WebAdmin takeover.

  • CVE-2026-81574: Missing sanitization can be used to reliably crash CodeMeter and force the logger to disclose sensitive information.

  • CVE-2026-81575: Missing bounds checking can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

  • CVE-2026-81576: Due to a cryptographically weak session ID, an attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

Affected Product(s)

Model no. Product name Affected versions
CodeMeter User Runtime Kit for Windows 10 TruTops Boost <21.04.26, TecZone Cut Laser 26.7, Programming Tube <7.5, Oseon <8.04.26, Oseon 8.04.26, TecZone Laser <26.7, TruTops Cell 2.105.4, TruTops Mark 3D 6.6.2, TRUMPF License Expert 2.4.2, TecZone Bend 26.8, TruTops Boost 21.04.26, TruTops Cell <2.105.4, TruTops Weld 10.0.133, TruTops Weld <10.0.133, TruTops Mark 3D <6.6.2, Programming Tube 7.5, TecZone Bend <26.8, TRUMPF License Expert <2.4.2
CodeMeter User Runtime Kit for Windows 10 TecZone Bend 26.8, TruTops Weld 10.0.133, Oseon <8.04.26, TruTops Boost 21.04.26, Programming Tube <7.5, TruTops Cell 2.105.4, TRUMPF License Expert 2.4.2, TruTops Weld <10.0.133, Oseon 8.04.26, TruTops Mark 3D 6.6.2, TecZone Laser <26.7, TecZone Bend <26.8, TecZone Cut Laser 26.7, TruTops Cell <2.105.4, Programming Tube 7.5, TruTops Boost <21.04.26, TRUMPF License Expert <2.4.2, TruTops Mark 3D <6.6.2
CodeMeter User Runtime Kit for Windows 10 8.40f, vers:generic/>=8.40|<8.41a
CodeMeter User Runtime Kit for Windows 11 TruTops Cell 2.105.4, TruTops Mark 3D <6.6.2, Oseon 8.04.26, TRUMPF License Expert 2.4.2, TruTops Boost <21.04.26, TruTops Cell <2.105.4, TecZone Bend <26.8, TecZone Bend 26.8, Oseon <8.04.26, TecZone Cut Laser 26.7, TRUMPF License Expert <2.4.2, Programming Tube <7.5, TruTops Mark 3D 6.6.2, TruTops Weld <10.0.133, Programming Tube 7.5, TecZone Laser <26.7, TruTops Boost 21.04.26, TruTops Weld 10.0.133
CodeMeter User Runtime Kit for Windows 11 TruTops Boost 21.04.26, TruTops Boost <21.04.26, TruTops Weld <10.0.133, Oseon 8.04.26, TruTops Mark 3D 6.6.2, TruTops Cell <2.105.4, TecZone Cut Laser 26.7, TRUMPF License Expert 2.4.2, TecZone Bend <26.8, TecZone Laser <26.7, Programming Tube <7.5, Programming Tube 7.5, Oseon <8.04.26, TecZone Bend 26.8, TRUMPF License Expert <2.4.2, TruTops Weld 10.0.133, TruTops Cell 2.105.4, TruTops Mark 3D <6.6.2
CodeMeter User Runtime Kit for Windows 11 9.00, vers:generic/>=9.0|<9.10

Vulnerabilities

Expand / Collapse all

Published
09/15/2026 10:18
Weakness
Improper Access Control (CWE-284)
Summary

If the Wibu CodeMeter User Runtime is configured as server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

References

Published
09/15/2026 10:18
Weakness
Use of Externally-Controlled Format String (CWE-134)
Summary

Format String Vulnerability in Logger

References

Published
09/15/2026 10:18
Weakness
Improper Link Resolution Before File Access ('Link Following') (CWE-59)
Summary

Local Privilege Escalation in CodeMeter Runtime on Windows

References

Published
09/15/2026 10:18
Weakness
Improper Handling of Length Parameter Inconsistency (CWE-130)
Summary

Improper Authentication of Session Handles

References

Published
09/15/2026 10:18
Weakness
Improper Handling of Length Parameter Inconsistency (CWE-130)
Summary

Missing Sanity Checks for Buffer Lengths

References

Remediation

If your installation is affected, the easiest fix is to install the latest Wibu CodeMeter Runtime from www.wibu.com/support/user/user-softwa... :
- for Windows 11 the CodeMeter User Runtime for Windows 9.10
- for Windows 10 the CodeMeter User Runtime for Windows 8.41a

TRUMPF will of course include these in upcoming product releases.

Acknowledgments

Trumpf SE + Co. KG thanks the following parties for their efforts:

  • CERT@VDE for coordination

Revision History

Version Date Summary
1.0.0 09/15/2026 09:00 Initial version