CVE-2026-9129Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a Viewer storage API request, causing the configured storage root to be discarded and allowing arbitrary files to be read from the server filesystem. Because the readable files include the server's master configuration, which stores database credentials, signing key locations, certificate passwords, and OAuth secrets, exploitation can lead to disclosure of all server secrets and full compromise of the server and its data. Cloud deployments are not affected, as they use object storage and do not enable this component.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-22: 2Patch / Workaround · 2026-05-22: 2Technical Details · 2026-05-22: 205-22
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Full discourse2 posts
  • yousukezan@yousukezan
    Disclosure

    PCB設計基盤「Altium Enterprise Server」に深刻な脆弱性2件が見つかった。認証済みユーザーだけでサーバー侵害や機密設計情報窃取が可能になる恐れがある。 問題はCVE-2026-9129とCVE-2026-9102で、いずれもCVSSスコア9.4のCritical評価を受けている。影響を受けるのはオンプレミス版Altium Enterprise Serverで、通常権限のワークスペース利用者でも権限境界を突破できる点が危険視されている。 CVE-2026-9129はViewerマイクロサービス内のStorageControllerに存在するパストラバーサル脆弱性だ。設計ビューアが図面やレイアウトを取得する際、URLエンコードされた絶対パスを適切に正規化しておらず、攻撃者は細工したAPIリクエストでサーバー上の任意ファイルを読み取れる。Windowsドライブレターやルートディレクトリを指定することで、設定済み保存領域を無視して任意パスへアクセスできるという。 一方のCVE-2026-9102はComparisonService内のGerberファイル比較機能に存在する。アップロード時のファイル名検証が欠如しており、「../」などを含む細工したContent-Dispositionヘッダーにより、任意パスへファイルを書き込める。攻撃者はWebシェル配置によるRCEや、アプリケーション本体や設定ファイル上書きによるDoS、バックドア設置が可能になる。 両脆弱性を組み合わせることで、内部ユーザーが読み取り・書き込み権限を連鎖的に悪用し、設計リポジトリ全体を掌握できる可能性がある。Altiumは修正版を公開済みで、管理者に対し緊急アップデートとAPIログ監査を推奨している。 https://securityonline.info/altium-enterprise-server-vulnerabilities-cve-2026-9129-rce/

    Post summary

    Two critical vulnerabilities (CVE-2026-9129 and CVE-2026-9102) in Altium Enterprise Server expose authenticated users to path traversal, arbitrary file read/write, and potential RCE. A patch has been released, with vendors urging emergency updates and API log auditing.

    040401.1K
    14.5K followersView on X
  • yousukezan@yousukezan
    Patch

    PCB設計基盤「Altium Enterprise Server」に深刻な脆弱性2件が見つかった。認証済みユーザーだけでサーバー侵害や機密設計情報窃取が可能になる恐れがある。 問題はCVE-2026-9129とCVE-2026-9102で、いずれもCVSSスコア9.4のCritical評価を受けている。影響を受けるのはオンプレミス版Altium Enterprise Serverで、通常権限のワークスペース利用者でも権限境界を突破できる点が危険視されている。 CVE-2026-9129はViewerマイクロサービス内のStorageControllerに存在するパストラバーサル脆弱性だ。設計ビューアが図面やレイアウトを取得する際、URLエンコードされた絶対パスを適切に正規化しておらず、攻撃者は細工したAPIリクエストでサーバー上の任意ファイルを読み取れる。Windowsドライブレターやルートディレクトリを指定することで、設定済み保存領域を無視して任意パスへアクセスできるという。 一方のCVE-2026-9102はComparisonService内のGerberファイル比較機能に存在する。アップロード時のファイル名検証が欠如しており、「../」などを含む細工したContent-Dispositionヘッダーにより、任意パスへファイルを書き込める。攻撃者はWebシェル配置によるRCEや、アプリケーション本体や設定ファイル上書きによるDoS、バックドア設置が可能になる。 両脆弱性を組み合わせることで、内部ユーザーが読み取り・書き込み権限を連鎖的に悪用し、設計リポジトリ全体を掌握できる可能性がある。Altiumは修正版を公開済みで、管理者に対し緊急アップデートとAPIログ監査を推奨している。 https://securityonline.info/altium-enterprise-server-vulnerabilities-cve-2026-9129-rce/

    Post summary

    The article announces two critical CVEs (CVE-2026-9129 and CVE-2026-9102) affecting Altium Enterprise Server, explains the technical weaknesses, and reports that a patch is available with mitigation recommendations.

    000201.1K
    14.0K followersView on X

Explore more