CVE-2026-1009 Details
Description
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Successful exploitation allows the attacker’s payload to execute in the context of the victim’s authenticated Altium 365 session, enabling unauthorized access to workspace data, including design files and workspace settings. Exploitation requires user interaction to view a malicious forum post.
A stored cross-site scripting vulnerability has been identified in the Altium Forum. This issue arises from inadequate server-side input sanitization in forum post content, allowing authenticated attackers to inject arbitrary JavaScript. The injected scripts are executed when other users view the affected posts. Exploitation of this vulnerability requires user interaction to access the malicious forum post. Once executed, the attacker's payload runs in the context of the victim's authenticated Altium 365 session, potentially leading to unauthorized access to workspace data, including design files and workspace settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altium.com/platform/security-compliance/security-advisories | Altium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-284 | Improper Access Control | Altium |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Altium |
Affected Products
| Product | Versions |
|---|---|
| altium altium live | 1.2.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 15, 2026 | New CVE Received | Altium |