Executive brief
Altium 365 is a cloud-based platform used by engineers to manage electronics design data and collaboration. A security flaw in its search service allowed unauthorized individuals to access, modify, or delete search index data across different customer accounts. While the primary design files remained secure, an attacker could have viewed sensitive project names, folder structures, and user information, or disrupted the ability of legitimate users to find their work.
Technical details
A missing authentication vulnerability exists in the Altium 365 SearchService legacy SOAP endpoint. The endpoint fails to require session tokens or identity verification, allowing an unauthenticated network attacker to interact with a workspace's search index if they possess the target workspace identifier. This flaw enables cross-tenant access, allowing attackers to read indexed metadata (project names, folder names, user metadata) and perform unauthorized injection, modification, or deletion of search index entries. While the underlying vault data is not directly affected, the integrity and availability of search results are compromised. This issue affects Altium 365 cloud deployments but does not impact the on-premise Altium Enterprise Server.
Affected products
- Altium 365 SearchService Cloud deployments prior to May 2026
Timeline
- 2026-05-21: disclosed: Vulnerability published in NVD and Altium advisories.