Server Certificate Validation Flaw in Altium Designer by Altium
CVE-2025-27377

5.3MEDIUM

Key Information:

Vendor

Altium

Vendor
CVE Published:
22 January 2026

What is CVE-2025-27377?

Altium Designer version 24.9.0 contains a vulnerability related to the lack of validation for self-signed server certificates during cloud connections. This oversight enables attackers to conduct man-in-the-middle (MITM) attacks, where they can intercept or manipulate communication between the client and server. As a result, sensitive information such as authentication credentials and proprietary design data may be exposed to unauthorized entities, posing a significant risk to users relying on secure cloud interactions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Altium Designer Web 24.9 <= 25.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.