๐Ÿ” CVE Alert

CVE-2026-81581

HIGH 8.8

User input in WibuKey is used (without proper sanitization) to compute the address of a pointer, which can be exploited to let the user point to any storage, to which Windows responds with a denial of service.

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).

CWE CWE-119
Vendor wibu-systems-ag
Product wibukey
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for wibu-systems-ag wibukey

Be the first to know when new high vulnerabilities affecting wibu-systems-ag wibukey are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

wibu-systems-ag / wibukey
0 < 6.71

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cdn.wibu.com: https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-100057.pdf

Credits

๐Ÿ” KEUM SUNG from Team_F1_Driver