Path Traversal Vulnerability in Altium Enterprise Server Vault Service
CVE-2026-11419
What is CVE-2026-11419?
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController, which stems from insufficient validation of user-controlled path components in image upload requests. This vulnerability allows an authenticated user to submit a deliberately crafted absolute path, effectively overriding the configured storage root and permitting arbitrary file writes to any location on the server's filesystem that is writable by the service account. As a result, this flaw can lead to the unauthorized creation of content-controlled files in web-accessible directories, potentially leading to overwriting important application binaries or configuration files. Consequently, there is a risk of escalation to remote code execution, service takeover, or denial of service. It is important to note that Altium 365 cloud deployments are not affected, as the vulnerable endpoint is not accessible and the cloud architecture is designed to mitigate the risks associated with file writes.
Affected Version(s)
Altium Enterprise Server Web 0 < 8.1.1
