CVE-2026-9102
Altium Altium Enterprise Server
A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended temporary upload directory and write arbitrary files to any location on the server filesystem. Because content-controlled files can be written to web-accessible directories, this can be escalated to remote code execution in the context of the service account. It can also be used to overwrite application...
- CVSS
- 9.4
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.05.21