Back

CRITICAL

Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File Write

Published May 20, 2026

Description

A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended temporary upload directory and write arbitrary files to any location on the server filesystem.

Because content-controlled files can be written to web-accessible directories, this can be escalated to remote code execution in the context of the service account. It can also be used to overwrite application binaries or configuration files, leading to service takeover or denial of service.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Altium
Published May 20, 2026
Updated May 20, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Deferred
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Altium
Published May 20, 2026
Updated May 20, 2026
Exploited since n/a
EUVD-2026-31146