CVE-2026-9152 Details
Description
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticated network attacker who can reference a target workspace's identifier can interact with that workspace's search index, crossing tenant boundaries. Successful exploitation allows reading a workspace's indexed contents (such as component data, project and folder names, and user metadata) and injecting, modifying, or deleting search index entries. These operations affect the search index only, not the underlying vault data, but they can disclose sensitive workspace information and compromise the integrity and availability of search results. Altium 365 cloud deployments are affected; on-premise Altium Enterprise Server is not affected.
A missing authentication vulnerability in Altium 365's SearchService allows unauthenticated network attackers to access and manipulate search index operations via a legacy SOAP endpoint. This vulnerability affects all Altium 365 cloud deployments but not on-premise Altium Enterprise Server. The issue arises because the SOAP endpoint exposes search index operations without requiring authentication, session tokens, or identity verification. Attackers who can reference a target workspace's identifier can interact with that workspace's search index, crossing tenant boundaries. Exploitation of this vulnerability enables the reading of indexed contents, such as component data, project and folder names, and user metadata, as well as the injection, modification, or deletion of search index entries. While these operations only impact the search index and not the underlying vault data, they can reveal sensitive workspace information and disrupt the integrity and availability of search results.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altium.com/platform/security-compliance/security-advisories | Altium | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | Altium |
| CWE-639 | Authorization Bypass Through User-Controlled Key | Altium |
Affected Products
| Product | Versions |
|---|---|
| Altium 365 SearchService | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Altium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | New CVE Received | Altium |
Volerion