CVE-2026-9152Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticated network attacker who can reference a target workspace's identifier can interact with that workspace's search index, crossing tenant boundaries. Successful exploitation allows reading a workspace's indexed contents (such as component data, project and folder names, and user metadata) and injecting, modifying, or deleting search index entries. These operations affect the search index only, not the underlying vault data, but they can disclose sensitive workspace information and compromise the integrity and availability of search results. Altium 365 cloud deployments are affected; on-premise Altium Enterprise Server is not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-21: 2Technical Details · 2026-05-21: 205-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-9152 A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, … https://www.cve.org/CVERecord?id=CVE-2026-9152

    Post summary

    The post announces a missing authentication vulnerability in Altium 365’s SearchService via a legacy SOAP endpoint, providing technical details but not a PoC, exploit, patch, or active exploitation evidence.

    00010289
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9152 A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, … https://www.cve.org/CVERecord?id=CVE-2026-9152 ----- Traducción: CVE-2026-9152 Exi… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-9152, stating that Altium 365's SearchService suffers from a missing authentication flaw via a legacy SOAP endpoint, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    79 followersView on X

Explore more