logo

Critical Altium Enterprise Server Flaws Grant RCE and Database Access

ID: 5ea29de0-90fc-5511-babb-2d1ca419d783

STIX ID: report--5ea29de0-90fc-5511-babb-2d1ca419d783

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

Altium Enterprise Server is affected by two critical vulnerabilities (CVE-2026-9129 and CVE-2026-9102) that allow authenticated workspace users to perform path traversal reads and un-sanitized file uploads that write arbitrary files. Together these flaws enable data exfiltration of secrets (such as master DB credentials) and full remote code execution or service takeover; the vendor has released patches and the report recommends immediate updates and auditing of user scopes and API logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.