Impact
A server-side request forgery flaw in Altium Enterprise Server’s UnifiedLogin service enables an unauthenticated network attacker to instruct the server to make arbitrary outbound HTTP requests. Because the forged requests originate from the server process itself, they bypass any host‑based checks. When the attacker directs the request to an internal endpoint that relies on local origin for authentication, the server can obtain confidential configuration data and stored credentials. With those credentials the attacker can gain an administrative session, giving complete control over the server and all services it hosts.
Affected Systems
Altium Enterprise Server, models that include the UnifiedLogin service and expose an internal configuration endpoint. Altium 365 cloud deployments are not affected because the vulnerable endpoint is disabled in cloud mode.
Risk and Exploitability
The vulnerability carries a CVSS score of 10 and an EPSS score of less than 1%, indicating a severe but currently unlikely exploitation pattern. Because it is reachable over the network without any authentication, a remote adversary can exploit it from any position that can reach the server. The lack of CISA KEV listing suggests no widespread exploitation yet, but the potential for full administrative takeover makes it a high‑priority risk.
OpenCVE Enrichment