CVE-2026-1181: Altium 365 Over-Permissive CORS Configuration Allows Credentialed Cross-Origin Workspace Access

Published Jan 19, 2026
·
Updated

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could access authenticated workspace APIs in the context of a logged-in user. When chained with vulnerabilities in those external applications, this misconfiguration enables unauthorized access to workspace data, administrative actions, and bypass of IP allowlisting controls, including in GovCloud environments.

Affected Software

1 affected component
Altium Altium 365

Event History

Jan 19, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Mar 25, 58030
Event
via FIRST·08:09 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-1181?

The severity of CVE-2026-1181 is considered high due to its potential for cross-customer data exposure.

2

How do I fix CVE-2026-1181?

To fix CVE-2026-1181, ensure that all user input in forum post content is properly sanitized on the server side.

3

What type of vulnerability is CVE-2026-1181?

CVE-2026-1181 is a stored cross-site scripting (XSS) vulnerability.

4

Who is affected by CVE-2026-1181?

CVE-2026-1181 affects users of the Altium 365 Forum who are exposed to untrusted content.

5

Can CVE-2026-1181 be exploited by unauthenticated users?

No, CVE-2026-1181 requires an authenticated attacker to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203