CVE-2026-1010
Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data.
When an administrator views the affected workflow, the injected payload executes in the administrator’s browser context, allowing privilege escalation, including creation of new administrator accounts, session token theft, and execution of administrative actions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
Altium · Altium Enterprise ServerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →