Junglewise Threat Intelligence

CVE-2026-14439: Altium Git Service path traversal in CloneRepository action

CVE-2026-14439 · Severity: info · CVSS 9.4 · Published 2026-07-01

Technologies: Altium 365. Vendors: Altium.

Executive brief

A security vulnerability in the Git Service used by Altium Enterprise Server and Altium 365 could allow an authorized user to move files to unauthorized locations on the server. By exploiting this flaw, an attacker could place malicious scripts in sensitive areas to take control of the service. In shared cloud environments, this could potentially allow one customer to access data belonging to others on the same system.

Technical details

A path traversal vulnerability exists in the Git Service (specifically the CloneRepository action) shared by Altium Enterprise Server and Altium 365. The service fails to validate user-supplied paths during a sequence of post-clone file-manipulation operations. An authenticated attacker with basic Git access can exploit this 'file-move primitive' to place attacker-controlled script content into directories where it is subsequently executed by the service. This results in remote code execution (RCE) under the Git Service account and, in multi-tenant Altium 365 deployments, could allow cross-tenant data access. Altium Enterprise Server is fixed in version 8.1.1, and Altium 365 has been remediated at the service level.

Affected products

  • Altium Enterprise Server prior to 8.1.1
  • Altium 365 All cloud workspaces (commercial and government)

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-06-05: disclosed: Original Altium security advisory date for related 8.1.1 fixes

References

Related threats