CVE-2026-81581
User input in WibuKey is used (without proper sanitization) to compute the address of a pointer, which can be exploited to let the user point to any storage, to which Windows responds with a denial of service.
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).
| CWE | CWE-119 |
| Vendor | wibu-systems-ag |
| Product | wibukey |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for wibu-systems-ag wibukey
Be the first to know when new high vulnerabilities affecting wibu-systems-ag wibukey are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
wibu-systems-ag / wibukey
0 < 6.71
References
Credits
๐ KEUM SUNG from Team_F1_Driver