Executive brief
Altium Enterprise Server and Altium 365 are affected by a security flaw in their GraphQL service, which is used for data queries. An authorized user can trick the server into making requests to internal systems that are normally hidden from the public internet. This could allow an attacker to view sensitive internal configuration data or scout the company's private network for further targets.
Technical details
A server-side request forgery (SSRF) vulnerability exists in a shared GraphQL service component. The root cause is a lack of URL validation and destination filtering when the server processes user-supplied input as a URL for outbound HTTP GET requests. An authenticated attacker can exploit this to reach internal network services and cloud metadata endpoints (IMDS) that are not publicly accessible. The exploit is limited to HTTP GET requests without custom headers, but the server returns the full response body to the attacker. Altium 365 has been patched at the service level, while on-premise Enterprise Server users must update to version 8.1.1.
Affected products
- Altium Enterprise Server versions prior to 8.1.1
- Altium 365 All cloud instances prior to June 2026 remediation
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory
- 2026-06-05: patched: Remediated in Altium 365 and fixed in Enterprise Server 8.1.1