Missing Authentication in Altium 365 SearchService Exposes Data Risks
CVE-2026-9152

10CRITICAL

Key Information:

Vendor

Altium

Vendor
CVE Published:
21 May 2026

What is CVE-2026-9152?

A missing authentication vulnerability in the Altium 365 SearchService allows unauthenticated network attackers to access search index operations. This issue arises from a legacy SOAP endpoint that permits interaction with a workspace's search index without required authentication or session tokens. An attacker with knowledge of a target workspace's identifier can read indexed contents, including sensitive project and user metadata, and can alter or delete search index entries. While these operations do not affect the underlying vault data, they can disclose critical workspace information and undermine the integrity of the search results. This vulnerability specifically impacts Altium 365 cloud deployments, while the on-premise Altium Enterprise Server remains unaffected.

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.