Executive brief
Altium Enterprise Server, a platform used for managing electronic design data, contains a security flaw in its file comparison service. An authenticated user can upload a specially crafted file that bypasses security restrictions to write data anywhere on the server's filesystem. This could allow an attacker to take full control of the server, steal sensitive design data, or disrupt business operations.
Technical details
A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. An authenticated workspace user can provide a manipulated filename in the multipart Content-Disposition header to escape the intended temporary directory. By writing files to web-accessible directories or overwriting application binaries/configuration files, an attacker can achieve remote code execution (RCE) in the context of the service account or cause a denial of service. The vulnerability is tracked as CVE-2026-9102 and has been assigned a CVSS 4.0 score of 9.4.
Affected products
- Altium Enterprise Server ComparisonService component
Timeline
- 2026-05-20: disclosed: CVE record published and added to NVD dataset