Description
A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request whose input is treated as a URL by the server and used to issue an outbound HTTP GET request without URL validation or destination filtering. The response body is then returned to the user.




This allows an authenticated attacker to reach internal services and metadata endpoints that would not otherwise be accessible from the public network, and to retrieve their contents. The impact is information disclosure and internal infrastructure reconnaissance; the request primitive is limited to HTTP GET with no custom headers. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.
Published: 2026-06-05
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery flaw exists in a GraphQL service shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a URL value that the service treats as an outbound HTTP GET target without performing any validation or restricting the destination. The server then returns the response body to the requester, allowing internal services and metadata endpoints to be accessed that would normally be unreachable from the public network. The attack vector is limited to HTTP GET requests without custom headers, but the impact is the exposure of sensitive system information and internal infrastructure reconnaissance.

Affected Systems

Altium Enterprise Server is impacted in all releases prior to version 8.1.1. The Altium 365 platform has addressed the issue at the service level, though the specific version range of the affected service is not enumerated in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity. No EPSS score is currently available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw requires authentication, an attacker must first compromise or obtain credentials for an authorized user; once authenticated, the attacker can explore the internal network via the SSRF mechanism. The lack of custom HTTP headers simplifies exploitation, but the limited outbound method may reduce the breadth of potential data exfiltration. Overall, the risk is significant for affected deployments, especially those exposed to untrusted or externally reachable authenticated users.

Generated by OpenCVE AI on June 5, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Altium Enterprise Server version 8.1.1 or later to eliminate the SSRF code path.
  • Implement network segmentation or firewall rules to restrict outbound HTTP GET requests from the application server to only approved destinations, thereby limiting the potential impact of any residual or undiscovered SSRF flanks.
  • Enable monitoring of GraphQL request logs for anomalous URL patterns and alert on repeated unauthorized attempts.

Generated by OpenCVE AI on June 5, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request whose input is treated as a URL by the server and used to issue an outbound HTTP GET request without URL validation or destination filtering. The response body is then returned to the user. This allows an authenticated attacker to reach internal services and metadata endpoints that would not otherwise be accessible from the public network, and to retrieve their contents. The impact is information disclosure and internal infrastructure reconnaissance; the request primitive is limited to HTTP GET with no custom headers. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.
Title Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure
Weaknesses CWE-200
CWE-918
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Altium

Published:

Updated: 2026-06-05T20:51:28.935Z

Reserved: 2026-06-05T20:20:57.336Z

Link: CVE-2026-11424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T22:16:47.330

Modified: 2026-06-05T22:16:47.330

Link: CVE-2026-11424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T23:00:11Z

Weaknesses