CVE-2026-92808
Last modified
CVE-2026-92808 is a critical-severity vulnerability rated 10/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself. One such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally.
Description
A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself. One such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally. Because the forged requests originate from the server process, that check is satisfied. An unauthenticated attacker can therefore retrieve stored credentials and use them to obtain an administrative session, resulting in full compromise of the server and all of its services. Altium 365 cloud deployments are not affected, as the affected endpoint is disabled in cloud mode.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Altium | Altium Enterprise Server | < 8.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-92808?
How severe is CVE-2026-92808?
How do I fix CVE-2026-92808?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92802kan through 0.6.0 fails to properly validate board creation …4.3
- CVE-2026-92803LibreTranslate through 1.9.6 omits the access_check decorato…5.3
- CVE-2026-92804Nango through 0.70.4 fails to validate caller-supplied conne…7.1
- CVE-2026-92805UVdesk Community Skeleton through 1.1.8 fails to authenticat…9.8
- CVE-2026-92806phpList versions before 3.6.17 fail to validate cross-site r…8.1
- CVE-2026-92807The Save as PDF Plugin by PDFCrowd plugin for WordPress is v…8.8
- CVE-2026-92809PrestaShop psgdpr versions through 1.4.3 fail to validate th…4.3
- CVE-2026-9281The Master Addons For Elementor – Widgets, Extensions, Theme…6.4
- CVE-2026-92810PrestaShop blockwishlist through 3.0.2 fails to validate wis…4.3
- CVE-2026-92811browserless versions 1.44.0 through 2.56.7 fail to enforce f…6.5
- CVE-2026-92812decap-server contains a path traversal vulnerability in the …6.8
- CVE-2026-92813Metabase through 0.63.18 fails to properly validate the unsp…4.9
Are you affected by CVE-2026-92808?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
