HOMEVULNERABILITIESCVE-2026-11429
CRITICAL

CVE-2026-11429

CWE-22Published: June 5, 2026· Updated: Jun 17, 2026

10.0
CVSS v3.1
EPSS:0.44%probability of exploitation in 30 daysPercentile:63.4th

Official Description

Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account. Because the file write operation completes before authentication is validated, the vulnerability can be exploited without any credentials, session, or prior knowledge of the system.

An unauthenticated network attacker can use this primitive to place executable content in directories where it is later executed by the service, resulting in remote code execution under the Vault Service account. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.

NVD Source

Risk Analysis

This critical vulnerability in Altium Enterprise Server and Altium 365's Vault Service ScriptsController allows unauthenticated attackers to upload arbitrary files. The flaw is due to insufficient validation of user-supplied filenames, enabling remote code execution under the service account. With a CVSS score of 10.0, this is an urgent threat.

No public exploit is currently known for this remotely exploitable vulnerability. The low attack complexity means it could be easily exploited if an exploit were to become available.

Recommended Action

Upgrade Altium Enterprise Server to version 8.1.1 or later to remediate this issue. Ensure all systems are kept up-to-date with the latest security patches.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-11429 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeX
Impact
Confidentiality
Integrity
Availability
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

All References (1)

Quick Facts

CVE IDCVE-2026-11429
CVSS Score10.0 / 10
SeverityCRITICAL
WeaknessCWE-22
CISA KEVNo
EPSS (30d)0.44%
PublishedJun 5, 2026

Related CVEs (CWE-22)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-11429 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.