CVE-2026-11423
CVE-2026-11423 is a critical path traversal vulnerability in Altium Enterprise Server Collaboration Service. Attackers can exploit it to read server configuration files containing privileged credentials, potentially gaining full server control. Altium 365 cloud deployments are unaffected.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Altium Enterprise Server Collaboration Service users
Real-world impact
Exploitation could lead to unauthorized administrative access and full server compromise via credential theft from master configuration files.
Why this severity
CVSS 9.4 (critical) due to high exploitability and severe impact (full system control possible).
What to do about it
- ›Validate and sanitize all user-supplied filenames in collaboration messages before server processing.
- ›Restrict server file system permissions to prevent unauthorized file access.
- ›Monitor server logs for suspicious filename patterns or unauthorized access attempts.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No official fix documented in provided sources. Mitigations based on vulnerability description.
Timeline
- Jun 5, 2026 · Jun 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.