Vulnary
← back to the feed
Critical· 10official fix available

CVE-2026-11429

Two upload endpoints in the Vault Service ScriptsController used by Altium Enterprise Server and Altium 365 do not validate user‑supplied filenames, allowing an unauthenticated attacker to write arbitrary files to any location the service can access. Because the write occurs before authentication, the attacker can place executable code that is later executed by the service, leading to remote code execution under the Vault Service account. Altium Enterprise Server is fixed in version 8.1.1, and the issue has been remediated at the service level for Altium 365 (commercial and government clouds).

publishedJun 5, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
1%
64th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 23, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Altium Enterprise Server and Altium 365 (Vault Service ScriptsController)

02

Real-world impact

An unauthenticated network attacker can achieve remote code execution with the privileges of the Vault Service account.

03

Why this severity

CVSS v4.0 base score 10 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction and resulting in high impact to confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01If you are running Altium Enterprise Server, upgrade to version 8.1.1 or later.
  2. 02If you are using Altium 365, the fix has been applied by Altium at the service level; no further action is required from you.

NVD-referenced vendor advisory (fix versions stated in NVD description)

05

Timeline

  1. Jun 5, 2026 · Jun 5, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 12d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 24, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →