Path Traversal and Hard-Coded Key Vulnerability in Altium Enterprise Server
CVE-2026-11414

10CRITICAL

Key Information:

Vendor

Altium

Vendor
CVE Published:
5 June 2026

What is CVE-2026-11414?

Altium Enterprise Server is susceptible to a significant security issue involving a hard-coded cryptographic key used for signing file download URLs within its Vault service. This key, which is consistent across all installations, permits an unauthenticated network attacker to forge valid download signatures. Consequently, attackers can retrieve files from the Vault's storage area without needing authentication or session credentials. Additionally, a path traversal vulnerability in the same download endpoint allows attackers to escape the configured storage root, facilitating access to arbitrary files on the server's filesystem. When combined, these vulnerabilities provide a method for attackers to gain access to sensitive server configurations and key material, potentially leading to full server compromise. Notably, Altium 365 cloud deployments are not affected due to the use of object storage for file management.

Affected Version(s)

Altium Enterprise Server Web 0 < 8.1.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.