Stored Cross-Site Scripting Vulnerability in Altium Support Center
CVE-2026-1011
What is CVE-2026-1011?
A stored cross-site scripting (XSS) vulnerability has been identified in the Altium Support Center. This issue arises from inadequate server-side input sanitization at the AddComment endpoint, allowing attackers to inject arbitrary HTML and JavaScript through manipulated POST requests. Although the frontend implements HTML escaping, the backend lacks sufficient validation, causing the injected content to be rendered without alteration when support cases are accessed by other users, including support personnel with higher privileges. This vulnerability can potentially lead to the execution of malicious JavaScript in a victim's browser, posing significant risks to user security and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Altium Live Web 0 <= 1.1.1.39
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
