Description
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself.




One such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally. Because the forged requests originate from the server process, that check is satisfied. An unauthenticated attacker can therefore retrieve stored credentials and use them to obtain an administrative session, resulting in full compromise of the server and all of its services. Altium 365 cloud deployments are not affected, as the affected endpoint is disabled in cloud mode.
Published: 2026-09-16
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full Server Compromise
Action: Immediate Patch
AI Analysis

Impact

A server-side request forgery flaw in Altium Enterprise Server’s UnifiedLogin service enables an unauthenticated network attacker to instruct the server to make arbitrary outbound HTTP requests. Because the forged requests originate from the server process itself, they bypass any host‑based checks. When the attacker directs the request to an internal endpoint that relies on local origin for authentication, the server can obtain confidential configuration data and stored credentials. With those credentials the attacker can gain an administrative session, giving complete control over the server and all services it hosts.

Affected Systems

Altium Enterprise Server, models that include the UnifiedLogin service and expose an internal configuration endpoint. Altium 365 cloud deployments are not affected because the vulnerable endpoint is disabled in cloud mode.

Risk and Exploitability

The vulnerability carries a CVSS score of 10 and an EPSS score of less than 1%, indicating a severe but currently unlikely exploitation pattern. Because it is reachable over the network without any authentication, a remote adversary can exploit it from any position that can reach the server. The lack of CISA KEV listing suggests no widespread exploitation yet, but the potential for full administrative takeover makes it a high‑priority risk.

Generated by OpenCVE AI on September 17, 2026 at 22:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest security patch for Altium Enterprise Server that fixes the UnifiedLogin SSRF issue
  • If a patch is not yet available, disable the UnifiedLogin service or block outbound connections to the internal configuration endpoint using a firewall or host‑based rule
  • Verify that all internal services require proper authentication and are not accessible via localhost or the server process alone

Generated by OpenCVE AI on September 17, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Altium
Altium enterprise Server
Vendors & Products Altium
Altium enterprise Server

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself. One such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally. Because the forged requests originate from the server process, that check is satisfied. An unauthenticated attacker can therefore retrieve stored credentials and use them to obtain an administrative session, resulting in full compromise of the server and all of its services. Altium 365 cloud deployments are not affected, as the affected endpoint is disabled in cloud mode.
Title Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise
Weaknesses CWE-306
CWE-918
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Altium Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Altium

Published:

Updated: 2026-09-17T14:56:49.460Z

Reserved: 2026-09-16T19:50:56.462Z

Link: CVE-2026-92808

cve-icon Vulnrichment

Updated: 2026-09-17T14:56:44.553Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:49.117

Modified: 2026-09-18T17:48:19.003

Link: CVE-2026-92808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-918

    Server-Side Request Forgery (SSRF)