Path Traversal Vulnerabilities in Altium Enterprise Server Network Installation Service
CVE-2026-11420

10CRITICAL

Key Information:

Vendor

Altium

Vendor
CVE Published:
5 June 2026

What is CVE-2026-11420?

The Network Installation Service (NIS) of Altium Enterprise Server is susceptible to two notable path traversal vulnerabilities. These weaknesses could allow unauthenticated attackers to write arbitrary files to any writable location within the server's filesystem. Additionally, these vulnerabilities could enable the reading of package archive files from the server. If exploited, an attacker could potentially leverage the ability to write files in web-accessible directories, resulting in escalating their access to remote code execution against the service account. Notably, deployments on Altium 365 cloud are safe, as the NIS feature is not included in the cloud offerings.

Affected Version(s)

Altium Enterprise Server Web 0 < 8.1.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.