Altium Enterprise Server是美国Altium公司的一款本地化数据管理服务器。 Altium Enterprise Server存在安全漏洞,该漏洞源于对用户提供的文件名处理不当导致路径遍历,导致经过身份验证的用户可读取任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Altium | Altium Enterprise Server | < 8.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Altium | Altium Enterprise Server | 0 ~ 8.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11420 | Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write | |
| CVE-2026-11429 | Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execut | |
| CVE-2026-11431 | Path Traversal in Altium Projects Service Allows Arbitrary File Read | |
| CVE-2026-11414 | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded | |
| CVE-2026-11424 | Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information D | |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Wr |
No comments yet