Threats Tagged 'cve-2026-9129'
View all threats tagged with 'cve-2026-9129'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-9129'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-9129 is a critical path traversal vulnerability in the Altium Enterprise Server Viewer StorageController component affecting on-premise deployments using local filesystem storage. An authenticated user can supply a specially crafted URL-encoded absolute file path in a Viewer storage API request, bypassing the configured storage root restriction and reading arbitrary files on the server. This includes sensitive files such as the server's master configuration containing database credentials, signing keys, certificate passwords, and OAuth secrets. Exploitation can lead to full disclosure of server secrets and complete compromise of the server and its data. Cloud deployments are not affected as they use object storage and do not enable this vulnerable component. No official patch or remediation guidance is currently available from the vendor. No known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 05/20/2026, 18:05:29 UTC Added: 05/20/2026, 19:34:46 UTC |
Showing 1 to 1 of 1 result