Executive brief
Altium Enterprise Server and Altium 365 are platforms used for electronic design management and collaboration. A security flaw in their Git Service allows an authorized user to move files to unauthorized locations on the server. This could allow an attacker to take full control of the server, execute malicious code, or access sensitive data belonging to other organizations on shared infrastructure.
Technical details
A path traversal vulnerability (CWE-22) exists in the Git Service component due to a lack of validation on user-supplied paths during post-clone file-manipulation operations. An authenticated attacker with basic Git access can exploit this 'file-move primitive' to place malicious scripts into executable directories, leading to remote code execution (CWE-94) under the service account. In multi-tenant Altium 365 environments, this flaw could be used to bypass tenant isolation and access data belonging to other customers. Altium Enterprise Server users should upgrade to version 8.1.1, while Altium 365 has been patched at the service level.
Affected products
- Altium Enterprise Server versions prior to 8.1.1
- Altium 365 All versions prior to June 2026 remediation
Timeline
- 2026-06-05: advisory: CVE-2026-11429 published by Altium
- 2026-06-05: patched: Altium Enterprise Server 8.1.1 released; Altium 365 remediated at service level