Path Traversal Vulnerability in Altium Enterprise Server Vault Service
CVE-2026-11419

9.4CRITICAL

Key Information:

Vendor

Altium

Vendor
CVE Published:
5 June 2026

What is CVE-2026-11419?

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController, which stems from insufficient validation of user-controlled path components in image upload requests. This vulnerability allows an authenticated user to submit a deliberately crafted absolute path, effectively overriding the configured storage root and permitting arbitrary file writes to any location on the server's filesystem that is writable by the service account. As a result, this flaw can lead to the unauthorized creation of content-controlled files in web-accessible directories, potentially leading to overwriting important application binaries or configuration files. Consequently, there is a risk of escalation to remote code execution, service takeover, or denial of service. It is important to note that Altium 365 cloud deployments are not affected, as the vulnerable endpoint is not accessible and the cloud architecture is designed to mitigate the risks associated with file writes.

Affected Version(s)

Altium Enterprise Server Web 0 < 8.1.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.