External risk intelligence

Altium Enterprise Server UnifiedLogin SSRF Credentials Theft

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-92808

The vulnerability exists in the UnifiedLogin service of an enterprise server product. Login services and identity portals are commonly deployed as internet-facing components to facilitate user authentication for enterprise resources, making this surface frequently reachable from the public internet.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in Altium Enterprise Server's UnifiedLogin service could allow an unauthenticated attacker to access sensitive server information and credentials by tricking the server into sending requests to internal systems. This could lead to a full compromise of the server and its services. Altium 365 cloud deployments are not affected.

  • Attackers can steal server credentials.
  • Compromise leads to full server takeover.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to the UnifiedLogin service, which is accessible over the network. This allows the attacker to trick the server into making requests to internal services. One of these internal services can then be used to retrieve credentials without any authentication, leading to full server compromise.

  • No authentication required to initiate.
  • Server makes requests to internal services.
  • Full server compromise and credential theft.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the UnifiedLogin service could allow an unauthenticated attacker to forge requests from the server. When supported, this could lead to the retrieval of stored credentials and an administrative session, resulting in a full compromise of the server and its services.

  • Server configuration and credentials at risk.
  • Forged requests can access internal services.
  • Full server compromise is a realistic consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

The UnifiedLogin service in Altium Enterprise Server is likely managed by an infrastructure or platform team responsible for maintaining the server's core services. The first step is to identify all instances of the affected server, determine their reachability and business criticality, and then locate the specific system owner to plan remediation, considering that cloud deployments are not impacted.

  • Identify affected server instances and owners.
  • Verify network reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Altium Enterprise Server?

Altium Enterprise Server is a platform that manages electronic design data and collaboration for engineering teams. It centralizes design files, components, and user identity, acting as the foundation for an organization's internal product development lifecycle. The software includes the UnifiedLogin service, which manages authentication and identity for users accessing these design resources.

What does Server-Side Request Forgery mean for CVE-2026-92808?

This vulnerability is a Server-Side Request Forgery (SSRF) flaw, classified under CWE-918. It means an attacker can manipulate the Altium server into making network requests on their behalf. Because the server is a trusted component within the internal network, it can reach restricted internal services that an outsider normally cannot access, bypassing traditional perimeter defenses.

How does an attacker trigger this vulnerability?

An attacker initiates this by sending a specially crafted, unauthenticated HTTP request to the UnifiedLogin service. The service incorrectly processes this input, causing the server to fetch data from an internal, sensitive endpoint. Importantly, this issue does not require the attacker to have a valid user account, as the flaw resides in the authentication service itself.

Is my Altium server reachable from the internet?

Halo Surface Signal indicates that login and identity portals are often exposed to the public internet to support remote user access. If your specific instance of Altium Enterprise Server is configured this way, the attack surface is significantly increased. Systems that are restricted to private, internal-only networks face a lower immediate risk of external exploitation.

What should I do first to address this CVE?

Begin by auditing your infrastructure to locate all running instances of Altium Enterprise Server. Confirm which ones are accessible over the network and verify if they are on-premises installations, as Altium 365 cloud deployments are not affected. Once you have an inventory, coordinate with your system owners to review the deployment configuration and apply upcoming vendor updates.

References