CVE-2026-11423: Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem.
Because the readable files include the server's master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable MCAD and Simulation file download handling (or disable the Collaboration Service file-download functionality) until a vendor patch is applied to prevent processing of user-supplied filenames for downloads.
Altium Enterprise Server Collaboration Service MCAD and Simulation file downloads = disabled - Compensating control
Restrict access to the Collaboration Service download endpoints to trusted IP addresses or internal networks at the network firewall or reverse proxy to prevent untrusted authenticated users from reaching the vulnerable functionality.
- Operational
Rotate credentials for privileged accounts stored in the server master configuration and invalidate existing sessions/tokens, since those credentials may be readable if the vulnerability was exploited.
- Operational
Audit server logs and collaboration message uploads for suspicious or crafted filenames and investigate for signs of exfiltration or unauthorized file access; if compromise is detected, perform remediation such as restoring from known-good backups and further incident response.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11423?
The severity of CVE-2026-11423 is critical with a CVSS score of 9.4.
How do I fix CVE-2026-11423?
To fix CVE-2026-11423, update to the latest version of Altium Enterprise Server Collaboration Service that addresses the path traversal vulnerability.
What are the implications of CVE-2026-11423?
CVE-2026-11423 allows a regular authenticated user to escalate privileges through crafted filenames, potentially compromising system security.
Who is affected by CVE-2026-11423?
Users of Altium Enterprise Server Collaboration Service are affected by CVE-2026-11423 due to its path traversal vulnerability.
When was CVE-2026-11423 published?
CVE-2026-11423 was published on June 5, 2026.