Server-Side Request Forgery in Altium Products by Altium
CVE-2026-11424
8.3HIGH
What is CVE-2026-11424?
A vulnerability in the GraphQL service component of Altium Enterprise Server and Altium 365 allows authenticated users to manipulate server requests. By submitting specially crafted input, the server treats this input as a URL, enabling it to issue outbound HTTP GET requests without adequate URL validation or destination filtering. This can lead to unintended access to internal services and metadata endpoints that should remain protected from public access. The vulnerability could potentially expose sensitive information and enable internal infrastructure reconnaissance.
Affected Version(s)
Altium 365 Web <= unspecified
Altium Enterprise Server Web 0 < 8.1.1
