Description
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload executes in the administrator’s browser context, allowing privilege escalation, including creation of new administrator accounts, session token theft, and execution of administrative actions.
INFO
Published Date :
2026-01-15T23:00:18.163Z
Last Modified :
2026-01-22T01:38:04.586Z
Source :
Altium
AFFECTED PRODUCTS
The following products are affected by CVE-2026-1010 vulnerability.
| Vendors | Products |
|---|---|
| Altium |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-1010.