PatchSiren cyber security CVE debrief
CVE-2026-9129 Altium CVE debrief
CVE-2026-9129 describes a critical path traversal flaw in Altium Enterprise Server Viewer StorageController. On on-premises deployments that use local filesystem storage, a regular authenticated user can submit a URL-encoded absolute path in a Viewer storage API request, causing the configured storage root to be bypassed and enabling arbitrary file reads from the server filesystem. The most concerning impact is disclosure of the master configuration and other sensitive files that can contain database credentials, signing key locations, certificate passwords, and OAuth secrets. The source description says cloud deployments are not affected because they use object storage and do not enable this component.
- Vendor
- Altium
- Product
- Altium Enterprise Server
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Organizations running on-premises Altium Enterprise Server deployments with local filesystem storage should prioritize this immediately, especially teams responsible for authentication, Viewer services, configuration secrets, and server hardening. Security operations teams should also review any environment where the server master configuration or adjacent credential material is stored locally.
Technical summary
The vulnerability is a path traversal issue in the Viewer StorageController caused by improper handling of file path route parameters. An authenticated user can provide a URL-encoded absolute path, such as an encoded drive letter, in a Viewer storage API request. That input can discard the configured storage root and redirect file access to arbitrary filesystem locations. NVD lists CWE-22 and CWE-200, aligning with arbitrary file access and information disclosure. Because readable files may include the master configuration and secret material, the practical impact can extend beyond file disclosure to full server and data compromise.
Defensive priority
Critical priority. The issue is remotely reachable, requires only low-privilege authenticated access, and can expose high-value secrets that may enable broader compromise. For on-prem deployments using local filesystem storage, treat this as an urgent remediation item.
Recommended defensive actions
- Confirm whether the deployment is on-premises and uses local filesystem storage; according to the source description, cloud deployments are not affected.
- Review the vendor advisory reference and apply the vendor-recommended fix or mitigation as soon as it is available.
- Restrict access to Viewer storage APIs to trusted administrative networks and roles only until remediation is complete.
- Audit server-side configuration and secret handling, especially master configuration files, database credentials, signing key locations, certificate passwords, and OAuth secrets.
- Rotate any secrets that may have been exposed if the vulnerable configuration was reachable in production.
- Monitor authentication logs and file-access anomalies for unusual URL-encoded path inputs or requests to Viewer storage endpoints.
Evidence notes
This debrief is based on the supplied NVD record for CVE-2026-9129, which states that the issue is a path traversal vulnerability in Altium Enterprise Server Viewer StorageController affecting on-premises deployments that use local filesystem storage. The record says an authenticated user can supply a URL-encoded absolute path to cause the storage root to be discarded and arbitrary files to be read. The supplied description further states that readable files can include the master configuration with database credentials, signing key locations, certificate passwords, and OAuth secrets, and that cloud deployments are not affected. NVD metadata lists CWE-22 and CWE-200 and a CVSS 4.0 vector consistent with high confidentiality, integrity, and availability impact. The source reference points to Altium's security advisories page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9129 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9129
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9129 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9129
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.altium.com/platform/security-compliance/security-advisories
4760f414-e1ae-4ff1-bdad-c7a9c3538b79
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.