CVE-2026-11423: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Altium Altium Enterprise Server
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem. Because the readable files include the server's master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
AI Analysis
Technical Summary
CVE-2026-11423 is a path traversal vulnerability in Altium Enterprise Server's Collaboration Service. The issue arises from improper handling of user-supplied filenames in the MCAD and Simulation file download flows. Authenticated users can submit crafted filenames in collaboration messages, which are used without validation to build server download paths. This allows reading arbitrary files on the server filesystem, including the master configuration file that stores credentials for privileged accounts. Successful exploitation can enable an attacker to authenticate as a system administrator and gain full control of the server. Altium 365 cloud deployments are not affected by this vulnerability. No vendor advisory or patch information is currently available.
Potential Impact
An authenticated user can read arbitrary files on the server, including sensitive configuration files containing credentials for privileged accounts. This can lead to privilege escalation to system administrator level and full server compromise. The vulnerability is rated critical with a CVSS 4.0 score of 9.4, indicating high attack vector and impact metrics. Cloud deployments of Altium 365 are not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user permissions and monitor for suspicious activity related to file downloads in the Collaboration Service. Avoid exposing the affected service to untrusted users.
CVE-2026-11423: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Altium Altium Enterprise Server
Description
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem. Because the readable files include the server's master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
CVSS v4.0
Score 9.4critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11423 is a path traversal vulnerability in Altium Enterprise Server's Collaboration Service. The issue arises from improper handling of user-supplied filenames in the MCAD and Simulation file download flows. Authenticated users can submit crafted filenames in collaboration messages, which are used without validation to build server download paths. This allows reading arbitrary files on the server filesystem, including the master configuration file that stores credentials for privileged accounts. Successful exploitation can enable an attacker to authenticate as a system administrator and gain full control of the server. Altium 365 cloud deployments are not affected by this vulnerability. No vendor advisory or patch information is currently available.
Potential Impact
An authenticated user can read arbitrary files on the server, including sensitive configuration files containing credentials for privileged accounts. This can lead to privilege escalation to system administrator level and full server compromise. The vulnerability is rated critical with a CVSS 4.0 score of 9.4, indicating high attack vector and impact metrics. Cloud deployments of Altium 365 are not impacted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated user permissions and monitor for suspicious activity related to file downloads in the Collaboration Service. Avoid exposing the affected service to untrusted users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Altium
- Date Reserved
- 2026-06-05T20:07:07.335Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2339d3e29bf47b50c1ce71
Added to database: 06/05/2026, 21:04:19 UTC
Last enriched: 06/13/2026, 09:51:05 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.