Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Altium — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting Altium. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Altium develops electronic design automation software for PCB creation and component management. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and insecure design. The company maintains a moderate CVE count with 9 records, though no major public security incidents have been widely reported. Security researchers have identified issues in web interfaces and file parsing components that could allow unauthorized access or system compromise. While not a high-risk target, the software's complexity and integration with hardware design processes necessitate regular security assessments to mitigate potential exploitation risks in engineering environments.

CVE ID Title CVSS Severity Published
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise — Altium Enterprise Server CWE-918 10.0 Critical 2026-09-16
CVE-2026-14439 Path Traversal in Altium Git Service Allows Remote Code Execution — Altium Enterprise Server CWE-22 - - 2026-07-01
CVE-2026-11431 Path Traversal in Altium Projects Service Allows Arbitrary File Read — Altium Enterprise Server CWE-22 - - 2026-06-05
CVE-2026-11429 Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execution — Altium Enterprise Server CWE-22 - - 2026-06-05
CVE-2026-11424 Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure — Altium Enterprise Server CWE-918 - - 2026-06-05
CVE-2026-11423 Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation — Altium Enterprise Server CWE-22 - - 2026-06-05
CVE-2026-11420 Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read — Altium Enterprise Server CWE-22 - - 2026-06-05
CVE-2026-11419 Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write — Altium Enterprise Server CWE-22 - - 2026-06-05
CVE-2026-11414 Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path Traversal — Altium Enterprise Server CWE-798 - - 2026-06-05
CVE-2026-9152 Unauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index Destruction — Altium 365 CWE-306 - - 2026-05-21
CVE-2026-9129 Path Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File Read — Altium Enterprise Server CWE-22 - - 2026-05-20
CVE-2026-9102 Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File Write — Altium Enterprise Server CWE-22 - - 2026-05-20
CVE-2025-27380 HTML Injection Leading to Script Execution in Altium Enterprise Server — AES CWE-79 7.6 High 2026-01-22
CVE-2025-27379 Stored Cross-Site Scripting in AES BOM Viewer — AES CWE-79 6.8 Medium 2026-01-22
CVE-2025-27378 SQL Injection in AES Due to Inactive SQL Parsing Configuration — AES CWE-89 8.6 High 2026-01-22
CVE-2025-27377 Missing Validation of Self-Signed Certificates in Altium Designer Allows Man-in-the-Middle Attacks — Altium Designer CWE-295 5.3 Medium 2026-01-22
CVE-2026-1181 Altium 365 Over-Permissive CORS Configuration Allows Credentialed Cross-Origin Workspace Access — Altium 365 CWE-942 9.0 Critical 2026-01-19
CVE-2026-1011 Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint — Altium Live CWE-79 6.1 Medium 2026-01-15
CVE-2026-1010 Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation — Altium Enterprise Server CWE-79 8.0 High 2026-01-15
CVE-2026-1009 Stored Cross-Site Scripting in Altium Live Forum Leading to Cross-Customer Data Exposure — Altium Live CWE-79 9.0 Critical 2026-01-15
CVE-2026-1008 Stored Cross-Site Scripting in Altium Live User Profile Fields — Altium Live CWE-79 7.6 High 2026-01-15

This page lists every published CVE security advisory associated with Altium. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.