CRITICAL🇵🇱 Wersja polska

CVE-2026-1181

CVSS 9.0v3.1pub. 2026-01-19upd. 2026-04-15

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could access authenticated workspace APIs in the context of a logged-in user. When chained with vulnerabilities in those external applications, this misconfiguration enables unauthorized access to workspace data, administrative actions, and bypass of IP allowlisting controls, including in GovCloud environments.

🤖 AI Analysis
How it works

Incorrect CORS configuration in Altium 365 endpoints allowed authenticated cross-origin requests (with cookie/credential transmission) from other Altium subdomains, such as forum.live.altium.com. Malicious JavaScript code executed in the context of these subdomains could invoke protected workspace APIs on behalf of a logged-in user. The attack requires combining this misconfiguration with a separate vulnerability in one of the allowed subdomains, allowing the attacker to construct a scenario in which the victim visits a specially crafted page.

Impact

An attacker can gain unauthorized access to workspace data of a logged-in user, perform privileged administrative actions, and bypass access control mechanisms based on IP allowlisting, including in GovCloud environments.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.altium.com/platform/security-compliance/security-advisories). It is recommended to verify the CORS policy configuration in the Altium 365 environment and monitor workspace API access for unauthorized cross-origin requests.

Who is affected

Altium 365 – workspace endpoints (versions specified in vendor references); the issue also affected GovCloud environments

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References