Unvalidated File Upload Vulnerability in Altium Enterprise Server and Altium 365
CVE-2026-11429

10CRITICAL

Key Information:

Vendor

Altium

Vendor
CVE Published:
5 June 2026

What is CVE-2026-11429?

The Vault Service ScriptsController in Altium Enterprise Server and Altium 365 has an unvalidated file upload vulnerability. This issue allows an unauthenticated attacker to upload arbitrary files to any writable directory accessible by the service account, which can then lead to unauthorized execution of malicious code. Since the file operation occurs before the authentication check, the attacker does not need to possess valid credentials or prior knowledge of the system to exploit this vulnerability. This critical flaw highlights the necessity for rigorous file validation and secure coding practices.

Affected Version(s)

Altium 365 Web <= unspecified

Altium Enterprise Server Web 0 < 8.1.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joris Aerts, Tesla Inc.
.