Path Traversal and Hard-Coded Key Vulnerability in Altium Enterprise Server
CVE-2026-11414
What is CVE-2026-11414?
Altium Enterprise Server is susceptible to a significant security issue involving a hard-coded cryptographic key used for signing file download URLs within its Vault service. This key, which is consistent across all installations, permits an unauthenticated network attacker to forge valid download signatures. Consequently, attackers can retrieve files from the Vault's storage area without needing authentication or session credentials. Additionally, a path traversal vulnerability in the same download endpoint allows attackers to escape the configured storage root, facilitating access to arbitrary files on the server's filesystem. When combined, these vulnerabilities provide a method for attackers to gain access to sensitive server configurations and key material, potentially leading to full server compromise. Notably, Altium 365 cloud deployments are not affected due to the use of object storage for file management.
Affected Version(s)
Altium Enterprise Server Web 0 < 8.1.1
