Unvalidated File Upload Vulnerability in Altium Enterprise Server and Altium 365
CVE-2026-11429
10CRITICAL
What is CVE-2026-11429?
The Vault Service ScriptsController in Altium Enterprise Server and Altium 365 has an unvalidated file upload vulnerability. This issue allows an unauthenticated attacker to upload arbitrary files to any writable directory accessible by the service account, which can then lead to unauthorized execution of malicious code. Since the file operation occurs before the authentication check, the attacker does not need to possess valid credentials or prior knowledge of the system to exploit this vulnerability. This critical flaw highlights the necessity for rigorous file validation and secure coding practices.
Affected Version(s)
Altium 365 Web <= unspecified
Altium Enterprise Server Web 0 < 8.1.1
