PT-2026-3143 · Altium · Altium Workflow Engine
Joris Aerts
·
Published
2026-01-15
·
Updated
2026-01-16
·
CVE-2026-1010
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Altium Workflow Engine (affected versions not specified)
Description
A stored cross-site scripting (XSS) issue exists because of insufficient server-side input sanitization within workflow form submission APIs. An authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload executes in the administrator’s browser, potentially allowing privilege escalation, including the creation of new administrator accounts, session token theft, and the execution of administrative actions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altium Workflow Engine