PT-2026-47043 · Altium · Altium Enterprise Server Vault Service

CVE-2026-11419

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Altium Enterprise Server Vault Service (affected versions not specified)
Description A path traversal issue exists in the 'UploadController' due to improper validation of a user-controlled path component during image upload requests. An authenticated user can provide a crafted absolute path to bypass the configured storage root, enabling the writing of arbitrary files to any location on the server filesystem accessible by the service account. Since files can be written to web-accessible directories or used to overwrite configuration files and application binaries, this can lead to remote code execution, service takeover, or denial of service. Path traversal is a security flaw where an attacker can access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11419

Affected Products

Altium Enterprise Server Vault Service