PT-2026-47056 · Altium · Altium 365+1

CVE-2026-11424

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Altium Enterprise Server versions prior to 8.1.1 Altium 365 (affected versions not specified)
Description A server-side request forgery (SSRF) exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request where the input is treated as a URL and used to issue an outbound HTTP GET request without URL validation or destination filtering. The server then returns the response body to the user. This allows an attacker to access internal services and metadata endpoints that are not accessible from the public network, leading to information disclosure and internal infrastructure reconnaissance. The request primitive is limited to HTTP GET and does not support custom headers.
Recommendations Update Altium Enterprise Server to version 8.1.1. For Altium 365, the issue has been remediated at the service level.

Fix

Information Disclosure

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11424

Affected Products

Altium 365
Altium Enterprise Server