Missing Authentication in Altium 365 SearchService Exposes Data Risks
CVE-2026-9152
What is CVE-2026-9152?
A missing authentication vulnerability in the Altium 365 SearchService allows unauthenticated network attackers to access search index operations. This issue arises from a legacy SOAP endpoint that permits interaction with a workspace's search index without required authentication or session tokens. An attacker with knowledge of a target workspace's identifier can read indexed contents, including sensitive project and user metadata, and can alter or delete search index entries. While these operations do not affect the underlying vault data, they can disclose critical workspace information and undermine the integrity of the search results. This vulnerability specifically impacts Altium 365 cloud deployments, while the on-premise Altium Enterprise Server remains unaffected.
