Description
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area.




This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node.
Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.
Published: 2026-07-01
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw (CWE-22) exists in the Git Service component used by Altium Enterprise Server and Altium 365. The service processes a series of post‑clone file‑manipulation operations that include user‑supplied file paths without validation, allowing an authenticated user who has basic git read/write access to move files outside the intended repository boundaries. By placing a malicious script into a directory that the service later executes, the attacker can gain remote code execution under the Git Service account. In multi‑tenant Altium 365 instances, this flaw could also expose data belonging to other node. The vulnerability also allows the execution of arbitrary code (CWE-94) by injecting scripts that are later parsed and run by the service.

Affected Systems

Vulnerable deployments include Altium 365 and Altium Enterprise Server. All versions of Altium Enterprise Server prior to 8.1.1 are affected; the 8.1.1 release and later contain the fix. The issue also exists in Altium 365 until the service‑level remediation is applied, which has been rolled out to all shared multi‑tenant deployments. There is no specific product version information for Altium 365 beyond the service‑level patch.

Risk and Exploitability

The flaw has a CVSS base score of 9.4, indicating a very high severity. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is a credentialed vulnerability, requiring an authenticated user with basic git access to perform the malicious file moves. Attack Service account, and in shared multi‑tenant environments they may also obtain data from other tenants. Although exploitation requires legitimate credentials, the high severity and potential for lateral movement make this a considerable risk for affected environments.

Generated by OpenCVE AI on July 21, 2026 at 12:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Altium Enterprise Server to version 8.1.1 or later.
  • Apply the service‑level remediation to all shared multi‑tenant Altium 365 deployments; continue to apply updates as remediation becomes available for other deployments.
  • Restrict git clone and file‑manipulation permissions to trusted users and monitor for suspicious file movement outside the repository boundaries.

Generated by OpenCVE AI on July 21, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area. This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1. The issue has been remediated across Altium 365 shared multi-tenant deployments at the service level; remediation is in progress on remaining Altium 365 deployments. A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area. This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area. This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level. A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area. This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1. The issue has been remediated across Altium 365 shared multi-tenant deployments at the service level; remediation is in progress on remaining Altium 365 deployments.

Wed, 01 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files outside the intended repository area. This file-move primitive can be used to place attacker-controlled script content into directories where it is later executed by the service, resulting in remote code execution under the Git Service account. On multi-tenant Altium 365 deployments, this could have allowed access to data belonging to other tenants on the same infrastructure node. Altium Enterprise Server is fixed in 8.1.1; the issue has been remediated in Altium 365 (commercial and government cloud) at the service level.
Title Path Traversal in Altium Git Service Allows Remote Code Execution
Weaknesses CWE-22
CWE-94
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Altium

Published:

Updated: 2026-07-20T22:36:45.281Z

Reserved: 2026-07-01T22:14:07.575Z

Link: CVE-2026-14439

cve-icon Vulnrichment

Updated: 2026-07-02T12:25:22.683Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')