PT-2026-47058 · Altium · Altium 365+1

CVE-2026-11431

·

Published

2026-06-05

·

Updated

2026-06-05

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Altium Enterprise Server versions prior to 8.1.1 Altium 365 (affected versions not specified)
Description A path traversal issue exists in the Projects Service download endpoint. An authenticated user can provide a crafted path parameter that bypasses validation, enabling the reading of arbitrary files or entire directories returned as archives from the server filesystem. This can lead to the exposure of service configurations and credential material, which may facilitate further compromise. In multi-tenant Altium 365 deployments, this could expose credentials shared across services.
Recommendations Update Altium Enterprise Server to version 8.1.1. For Altium 365, the issue has been remediated at the service level.

Fix

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11431

Affected Products

Altium 365
Altium Enterprise Server