CVE-2026-11429
CWE-22Published: June 5, 2026· Updated: Jun 17, 2026
Official Description
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account. Because the file write operation completes before authentication is validated, the vulnerability can be exploited without any credentials, session, or prior knowledge of the system.
An unauthenticated network attacker can use this primitive to place executable content in directories where it is later executed by the service, resulting in remote code execution under the Vault Service account. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.
Risk Analysis
This critical vulnerability in Altium Enterprise Server and Altium 365's Vault Service ScriptsController allows unauthenticated attackers to upload arbitrary files. The flaw is due to insufficient validation of user-supplied filenames, enabling remote code execution under the service account. With a CVSS score of 10.0, this is an urgent threat.
No public exploit is currently known for this remotely exploitable vulnerability. The low attack complexity means it could be easily exploited if an exploit were to become available.
Upgrade Altium Enterprise Server to version 8.1.1 or later to remediate this issue. Ensure all systems are kept up-to-date with the latest security patches.
Technical Analysis
CVE-2026-11429 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (1)
Quick Facts
Related CVEs (CWE-22)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-11429 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts