Zurück zur Übersicht

TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

VDE-2026-091
Last update
15.09.2026 09:00
Published at
15.09.2026 09:00
Vendor(s)
Trumpf SE + Co. KG
External ID
VDE-2026-091
CSAF Document

Summary

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

Impact

The affected CodeMeter Runtime on Windows version has several vulnerabilities.

  • CVE-2026-81572: Allows under certain circumstances deletion of arbitrary files with System Privileges and could potentially enable Escalation of Privileges for an unprivileged account.

  • CVE-2026-81573: Allows commands intended for local or same-network clients only to be executed by arbitrary network peers. An attacker can overwrite values in Server.ini, enabling WebAdmin takeover.

  • CVE-2026-81574: Missing sanitization can be used to reliably crash CodeMeter and force the logger to disclose sensitive information.

  • CVE-2026-81575: Missing bounds checking can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

  • CVE-2026-81576: Due to a cryptographically weak session ID, an attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

Affected Product(s)

Model no. Product name Affected versions
CodeMeter User Runtime Kit for Windows 10 TruTops Cell 2.105.4, Programming Tube 7.5, TruTops Weld <10.0.133, TruTops Weld 10.0.133, TecZone Cut Laser 26.7, TecZone Laser <26.7, TruTops Mark 3D 6.6.2, TecZone Bend <26.8, Oseon <8.04.26, TRUMPF License Expert 2.4.2, TruTops Mark 3D <6.6.2, Programming Tube <7.5, TecZone Bend 26.8, TruTops Boost 21.04.26, TruTops Cell <2.105.4, TRUMPF License Expert <2.4.2, Oseon 8.04.26, TruTops Boost <21.04.26
CodeMeter User Runtime Kit for Windows 10 TecZone Laser <26.7, TruTops Boost <21.04.26, TruTops Weld 10.0.133, Programming Tube 7.5, TecZone Bend 26.8, TruTops Weld <10.0.133, TecZone Bend <26.8, TRUMPF License Expert 2.4.2, TruTops Mark 3D 6.6.2, TruTops Cell 2.105.4, Programming Tube <7.5, Oseon <8.04.26, Oseon 8.04.26, TruTops Boost 21.04.26, TecZone Cut Laser 26.7, TruTops Cell <2.105.4, TRUMPF License Expert <2.4.2, TruTops Mark 3D <6.6.2
CodeMeter User Runtime Kit for Windows 10 8.40f, vers:generic/>=8.40|<8.41a
CodeMeter User Runtime Kit for Windows 11 Oseon 8.04.26, TecZone Cut Laser 26.7, Oseon <8.04.26, TruTops Mark 3D <6.6.2, TruTops Mark 3D 6.6.2, Programming Tube 7.5, TruTops Cell 2.105.4, TruTops Boost <21.04.26, TecZone Laser <26.7, Programming Tube <7.5, TRUMPF License Expert 2.4.2, TRUMPF License Expert <2.4.2, TruTops Boost 21.04.26, TecZone Bend 26.8, TecZone Bend <26.8, TruTops Weld <10.0.133, TruTops Cell <2.105.4, TruTops Weld 10.0.133
CodeMeter User Runtime Kit for Windows 11 TruTops Cell 2.105.4, Oseon 8.04.26, TecZone Laser <26.7, TruTops Boost 21.04.26, TecZone Cut Laser 26.7, Oseon <8.04.26, TruTops Mark 3D <6.6.2, Programming Tube <7.5, TruTops Boost <21.04.26, Programming Tube 7.5, TRUMPF License Expert <2.4.2, TecZone Bend <26.8, TruTops Weld 10.0.133, TruTops Mark 3D 6.6.2, TRUMPF License Expert 2.4.2, TruTops Cell <2.105.4, TecZone Bend 26.8, TruTops Weld <10.0.133
CodeMeter User Runtime Kit for Windows 11 9.00, vers:generic/>=9.0|<9.10

Vulnerabilities

Expand / Collapse all

Published
15.09.2026 10:18
Weakness
Improper Access Control (CWE-284)
Summary

If the Wibu CodeMeter User Runtime is configured as server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

References

Published
15.09.2026 10:18
Weakness
Use of Externally-Controlled Format String (CWE-134)
Summary

Format String Vulnerability in Logger

References

Published
15.09.2026 10:18
Weakness
Improper Link Resolution Before File Access ('Link Following') (CWE-59)
Summary

Local Privilege Escalation in CodeMeter Runtime on Windows

References

Published
15.09.2026 10:18
Weakness
Improper Handling of Length Parameter Inconsistency (CWE-130)
Summary

Improper Authentication of Session Handles

References

Published
15.09.2026 10:18
Weakness
Improper Handling of Length Parameter Inconsistency (CWE-130)
Summary

Missing Sanity Checks for Buffer Lengths

References

Remediation

If your installation is affected, the easiest fix is to install the latest Wibu CodeMeter Runtime from www.wibu.com/support/user/user-softwa... :
- for Windows 11 the CodeMeter User Runtime for Windows 9.10
- for Windows 10 the CodeMeter User Runtime for Windows 8.41a

TRUMPF will of course include these in upcoming product releases.

Acknowledgments

Trumpf SE + Co. KG thanks the following parties for their efforts:

  • CERT@VDE for coordination

Revision History

Version Date Summary
1.0.0 15.09.2026 09:00 Initial version