CVE-2026-11423
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
05/06/2026
Última modificación:
05/06/2026
Descripción
*** Pendiente de traducción *** A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct the download path on the server without validation, allowing arbitrary files to be read from the server filesystem.<br />
<br />
<br />
<br />
<br />
Because the readable files include the server&#39;s master configuration, which stores credentials for privileged accounts, exploitation can lead to authenticating as a system administrator and gaining full control of the server. Altium 365 cloud deployments are not affected.
Impacto
Puntuación base 4.0
9.40
Gravedad 4.0
CRÍTICA



