Junglewise Threat Intelligence

CVE-2026-9129: Altium Enterprise Server path traversal in Viewer StorageController

CVE-2026-9129 · Severity: info · CVSS 9.4 · Published 2026-05-20

Vendors: Altium.

Executive brief

Altium Enterprise Server is a platform used for managing electronic design data and collaboration. A security flaw in the on-premise version allows an authenticated user to bypass folder restrictions and read any file on the server's hard drive. This could lead to the theft of sensitive configuration files, database credentials, and encryption keys, potentially resulting in a total compromise of the server and its data.

Technical details

A path traversal vulnerability (CWE-22) exists in the StorageController component of Altium Enterprise Server. The flaw is caused by improper handling of file path route parameters, where the application fails to validate URL-encoded absolute paths. An authenticated attacker can provide an encoded drive letter or absolute path in a Viewer storage API request, causing the application to discard the intended storage root and access the entire host filesystem. This allows for the retrieval of the server's master configuration file, which contains high-value secrets such as OAuth tokens, certificate passwords, and database credentials. This issue specifically affects on-premise deployments utilizing local filesystem storage; cloud deployments using object storage are unaffected.

Affected products

  • Altium Enterprise Server On-premise deployments using local filesystem storage

Timeline

  • 2026-05-20: disclosed: CVE-2026-9129 published by Altium

References