Impact
A path traversal flaw in the Altium Enterprise Server Vault Service UploadController allows an authenticated user to supply a crafted absolute path, causing the service to drop the configured storage root and write an arbitrary file anywhere on the server filesystem that the service account can reach. By overwriting web-accessible files, application binaries, or configuration files, an attacker can execute arbitrary code, take over the service, or deny service. The weakness maps to CWE-22 and CWE-434.
Affected Systems
The vulnerability affects Altium Enterprise Server, all iterations prior to the vendor’s published fix. Versions are not enumerated in the advisory, so any deployment that has exposed the UploadController endpoint is potentially vulnerable. The Altium 365 cloud service is not affected.
Risk and Exploitability
The CVSS score of 9.4 reflects a high severity risk. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access to the Vault Service, and the exploit path is the image upload endpoint. Because write permissions are available to the service account for arbitrary locations, a successful exploitation can lead to immediate service takeover or remote code execution.
OpenCVE Enrichment