PT-2026-47056 · Altium · Altium 365+1
CVE-2026-11424
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Altium Enterprise Server versions prior to 8.1.1
Altium 365 (affected versions not specified)
Description
A server-side request forgery (SSRF) exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request where the input is treated as a URL and used to issue an outbound HTTP GET request without URL validation or destination filtering. The server then returns the response body to the user. This allows an attacker to access internal services and metadata endpoints that are not accessible from the public network, leading to information disclosure and internal infrastructure reconnaissance. The request primitive is limited to HTTP GET and does not support custom headers.
Recommendations
Update Altium Enterprise Server to version 8.1.1.
For Altium 365, the issue has been remediated at the service level.
Fix
Information Disclosure
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altium 365
Altium Enterprise Server