CVE-2026-11414 Details
Description
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can forge valid download signatures and retrieve files from the Vault storage area without any authentication, session, or credentials. A separate path traversal vulnerability in the same download endpoint allows the configured storage root to be escaped, enabling reads of arbitrary files on the server filesystem. Combined, these issues allow an unauthenticated attacker to obtain sensitive server configuration and key material, which can lead to full server compromise. The vulnerability can be chained with CVE-2026-9152 to enumerate and bulk-download stored content. Altium 365 cloud deployments are not impacted in practice, as file storage uses object storage rather than the local filesystem.
A vulnerability exists in Altium Enterprise Server due to the use of a hard-coded cryptographic key that is identical across all installations. This key is used to sign file download URLs in the Vault service. An unauthenticated network attacker who can reach the server can forge valid download signatures, allowing them to retrieve files from the Vault storage area without any authentication, session, or credentials. Additionally, a separate path traversal vulnerability in the same download endpoint enables the escape of the configured storage root, allowing access to arbitrary files on the server filesystem. When combined, these issues permit an unauthenticated attacker to obtain sensitive server configuration and key material, potentially leading to full server compromise. This vulnerability can be chained with CVE-2026-9152 to enumerate and bulk-download stored content. Altium 365 cloud deployments are not impacted, as file storage uses object storage instead of the local filesystem.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altium.com/platform/security-compliance/security-advisories | Altium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Altium |
| CWE-798 | Use of Hard-coded Credentials | Altium |
Affected Products
| Product | Versions |
|---|---|
| altium on-prem enterprise server | < 8.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 5, 2026 | New CVE Received | Altium |