Path Traversal Vulnerability in Altium Enterprise Server and Altium 365
CVE-2026-11431

8.3HIGH

Key Information:

Vendor

Altium

Vendor
CVE Published:
5 June 2026

What is CVE-2026-11431?

A path traversal vulnerability exists within the Projects Service download endpoint in both Altium Enterprise Server and Altium 365. An authenticated user can manipulate the path parameter to bypass necessary validation checks, allowing them to read arbitrary files and directories from the server’s filesystem. This incident can result in sensitive information exposure such as service configurations and credential details, which attackers could leverage for further compromising the system. Additionally, in environments with multiple tenants on Altium 365, this vulnerability could lead to credentials being shared across different services being revealed. Remediation for Altium Enterprise Server was implemented in version 8.1.1, while the issue has been addressed at the service level for Altium 365.

Affected Version(s)

Altium 365 Web <= unspecified

Altium Enterprise Server Web 0 < 8.1.1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.