Junglewise Threat Intelligence

CVE-2026-11423: Altium Enterprise Server path traversal in Collaboration Service

CVE-2026-11423 · Severity: info · CVSS 9.4 · Published 2026-06-05

Vendors: Altium.

Executive brief

Altium Enterprise Server is an on-premise platform for managing electronics design data. A security flaw in its collaboration service allows an authorized user to bypass folder restrictions and read sensitive files from the server's hard drive. This could allow an attacker to steal administrative credentials and gain full control over the server and its hosted design data.

Technical details

A path traversal vulnerability (CWE-22) exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames within the MCAD and Simulation file download flows. An authenticated attacker can submit a collaboration message containing a specially crafted filename that escapes the intended directory. This allows the attacker to read arbitrary files from the server filesystem, including the master configuration file. Because this configuration file contains credentials for privileged accounts, the vulnerability can be escalated to full administrative control of the server (CWE-269). The issue affects on-premise deployments but does not impact Altium 365 cloud environments. A fix is available in version 8.0.4.

Affected products

  • Altium Enterprise Server All versions prior to 8.0.4

Timeline

  • 2026-06-05: disclosed: CVE published to NVD
  • 2026-06-05: advisory

References