Junglewise Threat Intelligence

CVE-2026-11420: Altium Enterprise Server path traversal in Network Installation Service

CVE-2026-11420 · Severity: info · CVSS 10 · Published 2026-06-05

Vendors: Altium.

Executive brief

Altium Enterprise Server is an on-premise platform used for managing electronics design data and software installations. A critical security flaw in its Network Installation Service allows an unauthenticated attacker to remotely read or write files on the server. This could lead to a total system takeover, the theft of sensitive design packages, or the disruption of engineering operations.

Technical details

Two path traversal vulnerabilities (CWE-22) exist within the Network Installation Service (NIS) component of Altium Enterprise Server. The flaws stem from a lack of authentication (CWE-306) and improper validation of file paths, allowing a remote, unauthenticated attacker to write arbitrary files to any writable location on the host filesystem or read package archives. By writing files to web-accessible directories or overwriting application binaries/configuration files, an attacker can escalate the vulnerability to remote code execution (RCE) under the context of the service account. This issue affects on-premise deployments but does not impact Altium 365 cloud services. A fix is available in version 8.0.4.

Affected products

  • Altium Enterprise Server All versions prior to 8.0.4

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References