PT-2026-47058 · Altium · Altium 365+1
CVE-2026-11431
·
Published
2026-06-05
·
Updated
2026-06-05
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Altium Enterprise Server versions prior to 8.1.1
Altium 365 (affected versions not specified)
Description
A path traversal issue exists in the Projects Service download endpoint. An authenticated user can provide a crafted
path parameter that bypasses validation, enabling the reading of arbitrary files or entire directories returned as archives from the server filesystem. This can lead to the exposure of service configurations and credential material, which may facilitate further compromise. In multi-tenant Altium 365 deployments, this could expose credentials shared across services.Recommendations
Update Altium Enterprise Server to version 8.1.1.
For Altium 365, the issue has been remediated at the service level.
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altium 365
Altium Enterprise Server