Junglewise Threat Intelligence

CVE-2026-92808: Altium Enterprise Server SSRF in UnifiedLogin service

CVE-2026-92808 · Severity: info · CVSS 10 · Published 2026-09-16

Executive brief

Altium Enterprise Server is a collaboration platform used by engineering teams to manage design projects and version control. An unauthenticated attacker can exploit a server-side request forgery vulnerability to trick the server into making internal HTTP requests, exposing stored credentials and configuration data. This allows attackers to gain administrative control of the server and compromise all services and data it hosts.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server prior to version 8.1.1. The vulnerability allows unauthenticated network attackers to cause the server to issue outbound HTTP requests to attacker-controlled destinations, including internal services that are normally unreachable from outside the server. The vulnerable endpoint in UnifiedLogin accepts user-controlled parameters without proper validation. An attacker can leverage this to access an internal service that exposes server configuration and credential material, which normally relies on request origin verification (local-only). Since forged requests originate from the server process itself, this check is bypassed, allowing attackers to retrieve stored credentials and gain administrative sessions. Altium 365 cloud deployments are not affected because the vulnerable endpoint is disabled in cloud mode. The issue is fixed in Altium Enterprise Server 8.1.1.

Affected products

  • Altium Enterprise Server prior to 8.1.1

Timeline

  • 2026-09-16: disclosed

References