PT-2026-42229 · Altium · Altium Enterprise Server

·

CVE-2026-9102

·

Published

2026-05-20

·

Updated

2026-05-20

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Altium Enterprise Server (affected versions not specified)
Description A path traversal issue exists in the ComparisonService due to insufficient filename sanitization within the Gerber file upload APIs. An authenticated workspace user can manipulate the Content-Disposition header in a multipart request to bypass the intended temporary upload directory and write arbitrary files anywhere on the server filesystem. This can lead to remote code execution if files are written to web-accessible directories, or result in service takeover and denial of service by overwriting application binaries or configuration files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9102

Affected Products

Altium Enterprise Server