CVE-2026-11431: Path Traversal in Altium Projects Service Allows Arbitrary File Read
A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a crafted path parameter that bypasses validation, allowing arbitrary files (including entire directories returned as archives) to be read from the server filesystem.
Because the readable files include service configuration and credential material, exploitation can be used to gather information enabling further compromise. The issue can be combined with CVE-2026-11424 to reach the cloud-side endpoint. On multi-tenant Altium 365 deployments, the readable configuration could have exposed credentials shared across services. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Altium Enterprise Serverto a version that resolves this vulnerability.Fixed in 8.1.1 - Compensating control
For Altium 365 customers, confirm with Altium that the service-level remediation has been applied to your tenant. If you cannot confirm remediation, restrict access to the Projects Service download endpoint (for example via firewall/ACL or network segmentation) and closely monitor access logs for suspicious file downloads.
- Operational
Rotate any configuration secrets, service credentials, API keys, and tokens that may have been exposed by the Projects Service download endpoint. Invalidate or replace affected credentials and update dependent services after applying fixes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11431?
The severity of CVE-2026-11431 is high, with a CVSS score of 8.3.
How does CVE-2026-11431 affect Altium products?
CVE-2026-11431 affects both Altium Enterprise Server and Altium 365 by allowing users to exploit a path traversal vulnerability to read arbitrary files.
What can an attacker do with CVE-2026-11431?
An attacker can potentially read sensitive files and entire directories by exploiting the path traversal vulnerability in CVE-2026-11431.
How can I mitigate the risks of CVE-2026-11431?
To mitigate the risks of CVE-2026-11431, ensure that your Altium products are updated to the latest patched versions provided by the vendor.
Who is affected by CVE-2026-11431?
Authenticated users of Altium Enterprise Server and Altium 365 may be affected by CVE-2026-11431 due to insufficient validation of path parameters.