CVE-2026-9152: Unauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index Destruction

Published May 21, 2026
·
Updated

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticated network attacker who can reference a target workspace's identifier can interact with that workspace's search index, crossing tenant boundaries.

Successful exploitation allows reading a workspace's indexed contents (such as component data, project and folder names, and user metadata) and injecting, modifying, or deleting search index entries. These operations affect the search index only, not the underlying vault data, but they can disclose sensitive workspace information and compromise the integrity and availability of search results. Altium 365 cloud deployments are affected; on-premise Altium Enterprise Server is not affected.

Affected Software

1 affected component
Altium Altium 365 SearchService

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Altium 365 SearchService legacy SOAP endpoint from your environment.

    Disable or remove the legacy SOAP endpoint that exposes search index operations to eliminate the unauthenticated access vector.

  2. Configuration

    Require authentication/session tokens or other identity verification for the legacy SOAP search endpoint so that unauthenticated requests cannot access or modify workspace search indexes.

    Altium 365 SearchService (legacy SOAP endpoint) authentication_required = true
  3. Compensating control

    Restrict network access to the legacy SOAP endpoint using firewall rules, ACLs, or a WAF so only trusted management IPs or internal networks can reach it until the endpoint is secured or removed.

  4. Operational

    Audit search index activity for unauthorized read, create, modify, or delete operations; rebuild or restore affected search indexes from known-good backups if tampering is detected and notify affected workspace owners.

Event History

May 21, 2026
CVE Published
via MITRE·12:47 AM
Data Sourced
via MITRE·12:47 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·03:50 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-9152?

CVE-2026-9152 is considered a critical vulnerability due to its potential for unrestricted access and data exfiltration.

2

How do I fix CVE-2026-9152?

To fix CVE-2026-9152, implement authentication for the SOAP endpoint in Altium 365 SearchService to prevent unauthorized access.

3

What type of attacks can be performed with CVE-2026-9152?

CVE-2026-9152 allows for cross-tenant data exfiltration and destruction of search indices due to lack of authentication.

4

Who is affected by CVE-2026-9152?

CVE-2026-9152 affects all users of Altium 365 SearchService that utilize the vulnerable SOAP endpoint without proper authentication.

5

Is there a workaround for CVE-2026-9152?

Currently, the recommended workaround for CVE-2026-9152 is to disable the vulnerable SOAP endpoint until proper authentication mechanisms are implemented.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203