CVE-2026-1010 is a stored cross-site scripting (XSS) vulnerability in Altium On-Prem Enterprise Server's Workflow Engine, stemming from inadequate input sanitization in workflow form submission APIs. A regular authenticated user can inject malicious JavaScript, which executes in an administrator's browser when they view the compromised workflow. This allows for privilege escalation, including creating new administrator accounts, stealing session tokens, and performing administrative actions. While rated Medium severity (CVSS 5.4), there is currently no public exploit code, Metasploit modules, or evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.1CPE matchmatch criteria | cpe:2.3:a:altium:on-prem_enterprise_server:8.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.