Critical Altium Enterprise Server Flaws Grant RCE and Database Access
ID: 5ea29de0-90fc-5511-babb-2d1ca419d783
STIX ID: report--5ea29de0-90fc-5511-babb-2d1ca419d783
Feed Name: securityonline.info
Altium Enterprise Server is affected by two critical vulnerabilities (CVE-2026-9129 and CVE-2026-9102) that allow authenticated workspace users to perform path traversal reads and un-sanitized file uploads that write arbitrary files. Together these flaws enable data exfiltration of secrets (such as master DB credentials) and full remote code execution or service takeover; the vendor has released patches and the report recommends immediate updates and auditing of user scopes and API logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
