CVE-2026-1008 Details
Description
A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace-based attribute parsing bypass techniques. The injected payload is persisted and executed when other users view the affected profile page, potentially allowing session token theft, phishing attacks, or malicious redirects. Exploitation requires an authenticated account and user interaction to view the crafted profile.
A stored cross-site scripting vulnerability has been identified in Altium 365 user profile text fields. This issue arises from inadequate server-side input sanitization, which enables authenticated users to inject arbitrary HTML and JavaScript payloads. The vulnerability exploits whitespace-based attribute parsing bypass techniques. Once injected, the payload is persisted and executed when other users view the affected profile page. This could lead to session token theft, phishing attacks, or malicious redirects. Exploitation requires an authenticated account and user interaction to view the modified profile.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altium.com/platform/security-compliance/security-advisories | Altium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Altium |
Affected Products
| Product | Versions |
|---|---|
| altium altium live | 1.2.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 16, 2026 | CVE Modified | Altium |
| Jan 15, 2026 | New CVE Received | Altium |