CVE-2026-11423
Received Received - Intake
Path Traversal in Altium Enterprise Server

Publication date: 2026-06-05

Last updated on: 2026-06-05

Assigner: Altium

Description
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem. Because the readable files include the server's master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-05
Last Modified
2026-06-05
Generated
2026-06-06
AI Q&A
2026-06-06
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
altium enterprise_server *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a path traversal issue in the Altium Enterprise Server Collaboration Service. It occurs because the server improperly handles user-supplied filenames in the MCAD and Simulation file download processes. An authenticated user can send a collaboration message with a specially crafted filename that the server uses to build the download path without validating it. This allows the user to read arbitrary files from the server's filesystem.


How can this vulnerability impact me? :

Exploiting this vulnerability can allow an attacker to read sensitive files on the server, including the server's master configuration files that contain credentials for privileged accounts. This can lead to the attacker authenticating as a system administrator and gaining full control over the server.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart