AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-1181

CRITICAL · CVSS 9 EPSS 0.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-01-19 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.0. It affects Java.

CVE
CVE-2026-1181
Severity
CRITICAL
CVSS
9
EPSS
0.31%
Java

Original NVD Description

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could access authenticated workspace APIs in the context of a logged-in user. When chained with vulnerabilities in those external applications, this misconfiguration enables unauthorized access to workspace data, administrative actions, and bypass of IP allowlisting controls, including in GovCloud environments.