Junglewise Threat Intelligence

CVE-2026-11431: Altium Enterprise Server and Altium 365 path traversal in Projects Service

CVE-2026-11431 · Severity: info · CVSS 8.3 · Published 2026-06-05

Technologies: Altium 365. Vendors: Altium.

Executive brief

Altium Enterprise Server and Altium 365, platforms used for electronic design management, contain a security flaw in their project download feature. An authorized user can bypass security checks to download sensitive files directly from the server's internal storage. This could allow an attacker to steal service credentials or configuration data, potentially leading to a broader breach of the design environment or other customer data.

Technical details

A path traversal vulnerability (CWE-22) exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. The flaw is caused by improper validation of path parameters, allowing an authenticated attacker to supply crafted input to access files outside the intended directory. Successful exploitation enables the retrieval of arbitrary files and directories (as archives), including sensitive configuration files and credentials. On multi-tenant Altium 365 deployments, this could expose secrets shared across different services. The issue is fixed in Altium Enterprise Server version 8.1.1 and has been remediated at the service level for Altium 365.

Affected products

  • Altium Enterprise Server prior to 8.1.1
  • Altium 365 All versions prior to service-level remediation

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats