Threats Tagged 'cve-2026-92808'
View all threats tagged with 'cve-2026-92808'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-92808'
Click on any threat for detailed analysis and mitigation recommendations
0 A critical server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated attacker can cause the server to make HTTP requests to arbitrary destinations, including internal services that expose sensitive configuration and credential data without authentication. This allows the attacker to retrieve stored credentials and gain administrative access, leading to full compromise of the server and its services. Altium 365 cloud deployments are not affected as the vulnerable endpoint is disabled in cloud mode. Join the discussion | GCVE Database | 09/16/2026, 21:32:48 UTC Added: 09/17/2026, 02:00:03 UTC |
0 A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server itself. One such internal service exposes server configuration and credential material without authentication, relying only on the request originating locally. Because the forged requests originate from the server process, that check is satisfied. An unauthenticated attacker can therefore retrieve stored credentials and use them to obtain an administrative session, resulting in full compromise of the server and all of its services. Altium 365 cloud deployments are not affected, as the affected endpoint is disabled in cloud mode. Join the discussion | CVE Database V5 | 09/16/2026, 20:06:28 UTC Added: 09/16/2026, 20:17:08 UTC |
Showing 1 to 2 of 2 results