You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This CVE record has been marked for NVD enrichment efforts.
Description
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account. Because the file write operation completes before authentication is validated, the vulnerability can be exploited without any credentials, session, or prior knowledge of the system.
An unauthenticated network attacker can use this primitive to place executable content in directories where it is later executed by the service, resulting in remote code execution under the Vault Service account. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Altium 365 de Altium, Description: Una vulnerabilidad de salto de ruta existe en el componente de Servicio Git compartido por Altium Enterprise Server y Altium 365. El servicio acepta una secuencia de operaciones de manipulación de archivos post-clonación que utilizan rutas proporcionadas por el usuario sin validación, permitiendo a un usuario autenticado con acceso git básico mover archivos arbitrarios fuera del área de repositorio prevista.
Esta primitiva de movimiento de archivos puede usarse para colocar contenido de script controlado por el atacante en directorios donde es ejecutado posteriormente por el servicio, resultando en ejecución remota de código bajo la cuenta del Servicio Git. En implementaciones multi-inquilino de Altium 365, esto podría haber permitido el acceso a datos pertenecientes a otros inquilinos en el mismo nodo de infraestructura. Altium Enterprise Server está corregido en 8.1.1; el problema ha sido remediado en Altium 365 a nivel de servicio.
[{"vendor":"Altium","product":"Altium Enterprise Server","defaultStatus":"unaffected","modules":["Vault Service (ScriptsController)"],"platforms":["Web"],"versions":[{"version":"0","lessThan":"8.1.1","versionType":"semver","status":"affected"}]},{"vendor":"Altium","product":"Altium 365","defaultStatus":"affected","modules":["Vault Service (ScriptsController)"],"platforms":["Web"],"versions":[{"version":"unspecified","status":"affected"}]}]
CVE Modified by Altium6/09/2026 1:17:00 PM
Action
Type
Old Value
New Value
Changed
Description
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area.
This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account. Because the file write operation completes before authentication is validated, the vulnerability can be exploited without any credentials, session, or prior knowledge of the system.
An unauthenticated network attacker can use this primitive to place executable content in directories where it is later executed by the service, resulting in remote code execution under the Vault Service account. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area.
This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 at the service level.