Altium 365和Altium Enterprise Server都是美国Altium公司的产品。Altium 365是一个产品设计和开发平台。Altium Enterprise Server是一款本地化数据管理服务器。 Altium 365和Altium Enterprise Server存在安全漏洞,该漏洞源于GraphQL服务组件中服务端请求伪造,导致经过身份验证的用户可发起出站HTTP GET请求并返回响应体。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Altium | Altium 365 | unspecified |
affected |
| Altium | Altium Enterprise Server | < 8.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Altium | Altium Enterprise Server | 0 ~ 8.1.1 | - |
|
| Altium | Altium 365 | unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11420 | Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write | |
| CVE-2026-11429 | Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execut | |
| CVE-2026-11431 | Path Traversal in Altium Projects Service Allows Arbitrary File Read | |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalati | |
| CVE-2026-11414 | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded | |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Wr |
No comments yet