CVE-2026-11423
Severity CVSS v4.0:
CRITICAL
Type:
CWE-22
Path Traversal
Publication date:
05/06/2026
Last modified:
05/06/2026
Description
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem.<br />
<br />
<br />
<br />
<br />
Because the readable files include the server&#39;s master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



