PT-2026-47036 · Altium · Altium Enterprise Server
CVE-2026-11414
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Altium Enterprise Server (affected versions not specified)
Description
The Vault service uses a hard-coded cryptographic key to sign file download URLs. Since this key is identical across all installations, an unauthenticated network attacker can forge valid signatures to retrieve files from the Vault storage area without credentials or a session. Additionally, a path traversal issue in the same download endpoint allows the storage root to be escaped, enabling the reading of arbitrary files on the server filesystem. These issues can be combined to obtain sensitive server configuration and key material, potentially leading to full server compromise. This can also be chained with other flaws to enumerate and bulk-download stored content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altium Enterprise Server