VYPR
Critical severityNVD Advisory· Published Jun 5, 2026· Updated Jun 8, 2026

CVE-2026-11423

CVE-2026-11423

Description

Altium Enterprise Server path traversal allows reading sensitive files, including credentials, leading to full server control.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Altium Enterprise Server path traversal allows reading sensitive files, including credentials, leading to full server control.

Vulnerability

A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem. Altium 365 cloud deployments are not affected. [1]

Exploitation

An attacker needs to be a regular authenticated user. The attacker submits a collaboration message containing a crafted filename. This filename is then used to construct the download path on the server without proper validation, enabling the attacker to read arbitrary files.

Impact

Successful exploitation allows an attacker to read arbitrary files from the server's filesystem. Because the readable files include the server's master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server.

Mitigation

Not yet disclosed in the available references. The provided reference [1] details other vulnerabilities but does not offer mitigation details for CVE-2026-11423.

AI Insight generated on Jun 5, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1