Altium 365和Altium Enterprise Server都是美国Altium公司的产品。Altium 365是一个产品设计和开发平台。Altium Enterprise Server是一款本地化数据管理服务器。 Altium 365和Altium Enterprise Server存在安全漏洞,该漏洞源于Projects Service下载端点接受用户提供的路径参数且绕过验证,可能导致经过身份验证的用户从服务器文件系统读取任意文件(包括整个目录作为归档返回),包括服务配置和凭据材料,从而收集
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Altium | Altium 365 | unspecified |
affected |
| Altium | Altium Enterprise Server | < 8.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Altium | Altium Enterprise Server | 0 ~ 8.1.1 | - |
|
| Altium | Altium 365 | unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11420 | Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write | |
| CVE-2026-11429 | Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execut | |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalati | |
| CVE-2026-11414 | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded | |
| CVE-2026-11424 | Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information D | |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Wr |
No comments yet