CVE-2026-11431: Path Traversal in Altium Projects Service Allows Arbitrary File Read

Published Jun 5, 2026
·
Updated

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a crafted path parameter that bypasses validation, allowing arbitrary files (including entire directories returned as archives) to be read from the server filesystem.

Because the readable files include service configuration and credential material, exploitation can be used to gather information enabling further compromise. The issue can be combined with CVE-2026-11424 to reach the cloud-side endpoint. On multi-tenant Altium 365 deployments, the readable configuration could have exposed credentials shared across services. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.

Affected Software

2 affected components
Altium Altium Enterprise Server<8.1.1
Altium Altium 365

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Altium Enterprise Server to a version that resolves this vulnerability.

    Fixed in 8.1.1
  2. Compensating control

    For Altium 365 customers, confirm with Altium that the service-level remediation has been applied to your tenant. If you cannot confirm remediation, restrict access to the Projects Service download endpoint (for example via firewall/ACL or network segmentation) and closely monitor access logs for suspicious file downloads.

  3. Operational

    Rotate any configuration secrets, service credentials, API keys, and tokens that may have been exposed by the Projects Service download endpoint. Invalidate or replace affected credentials and update dependent services after applying fixes.

Event History

Jun 5, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-11431?

The severity of CVE-2026-11431 is high, with a CVSS score of 8.3.

2

How does CVE-2026-11431 affect Altium products?

CVE-2026-11431 affects both Altium Enterprise Server and Altium 365 by allowing users to exploit a path traversal vulnerability to read arbitrary files.

3

What can an attacker do with CVE-2026-11431?

An attacker can potentially read sensitive files and entire directories by exploiting the path traversal vulnerability in CVE-2026-11431.

4

How can I mitigate the risks of CVE-2026-11431?

To mitigate the risks of CVE-2026-11431, ensure that your Altium products are updated to the latest patched versions provided by the vendor.

5

Who is affected by CVE-2026-11431?

Authenticated users of Altium Enterprise Server and Altium 365 may be affected by CVE-2026-11431 due to insufficient validation of path parameters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203