CVE-2026-11420 — Altium On-prem_enterprise_server: Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive files from the server. No authentication, session, or credentials are required. Because content-controlled files can be written to web-accessible directories, or used to overwrite application binaries or configuration files, e CVSSv3.1 9.8 (CRITICAL) · EPSS 50th percentile