PT-2026-3143 · Altium · Altium Workflow Engine

Joris Aerts

·

Published

2026-01-15

·

Updated

2026-01-16

·

CVE-2026-1010

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Altium Workflow Engine (affected versions not specified)
Description A stored cross-site scripting (XSS) issue exists because of insufficient server-side input sanitization within workflow form submission APIs. An authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload executes in the administrator’s browser, potentially allowing privilege escalation, including the creation of new administrator accounts, session token theft, and the execution of administrative actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1010

Affected Products

Altium Workflow Engine