CVE-2026-11423

Severity CVSS v4.0:
CRITICAL
Type:
CWE-22 Path Traversal
Publication date:
05/06/2026
Last modified:
05/06/2026

Description

A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem.<br /> <br /> <br /> <br /> <br /> Because the readable files include the server&amp;#39;s master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.