# CVE-2026-81579

## Summary

- **CVE ID:** CVE-2026-81579
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-123
- **Published:** Aug 27, 2026
- **Last Modified:** Aug 28, 2026

## Description

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

## Affected Products

- wibu-systems-ag — wibukey (0)

## References

- [CNA](https://cdn.wibu.com/fileadmin/wibu_downloads/security_advisories/AdvisoryWIBU-100031.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._