CVE-2026-11429
Two upload endpoints in the Vault Service ScriptsController used by Altium Enterprise Server and Altium 365 do not validate user‑supplied filenames, allowing an unauthenticated attacker to write arbitrary files to any location the service can access. Because the write occurs before authentication, the attacker can place executable code that is later executed by the service, leading to remote code execution under the Vault Service account. Altium Enterprise Server is fixed in version 8.1.1, and the issue has been remediated at the service level for Altium 365 (commercial and government clouds).
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Altium Enterprise Server and Altium 365 (Vault Service ScriptsController)
Real-world impact
An unauthenticated network attacker can achieve remote code execution with the privileges of the Vault Service account.
Why this severity
CVSS v4.0 base score 10 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction and resulting in high impact to confidentiality, integrity, and availability.
What to do about it
- 01If you are running Altium Enterprise Server, upgrade to version 8.1.1 or later.
- 02If you are using Altium 365, the fix has been applied by Altium at the service level; no further action is required from you.
NVD-referenced vendor advisory (fix versions stated in NVD description)
Timeline
- Jun 5, 2026 · Jun 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.