PT-2026-47043 · Altium · Altium Enterprise Server Vault Service
CVE-2026-11419
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Altium Enterprise Server Vault Service (affected versions not specified)
Description
A path traversal issue exists in the 'UploadController' due to improper validation of a user-controlled path component during image upload requests. An authenticated user can provide a crafted absolute path to bypass the configured storage root, enabling the writing of arbitrary files to any location on the server filesystem accessible by the service account. Since files can be written to web-accessible directories or used to overwrite configuration files and application binaries, this can lead to remote code execution, service takeover, or denial of service. Path traversal is a security flaw where an attacker can access files and directories that are stored outside the web root folder.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altium Enterprise Server Vault Service