A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-11419

CVE-2026-11419: Altium Enterprise Server Path Traversal

CVE-2026-11419 is a path traversal vulnerability in Altium Enterprise Server Vault Service that allows authenticated attackers to write files to arbitrary locations. This post covers the technical details, affected systems, and mitigation.

Published: June 11, 2026

CVE-2026-11419 Overview

CVE-2026-11419 is a path traversal vulnerability in the Altium Enterprise Server Vault Service UploadController. The flaw stems from improper validation of a user-controlled path component in image upload requests [CWE-22]. An authenticated user can supply a crafted absolute path that bypasses the configured storage root, writing arbitrary files anywhere the service account can write.

Attackers can escalate the file-write primitive to remote code execution, service takeover, or denial of service. Web-accessible directories, application binaries, and configuration files are all viable targets. Altium 365 cloud deployments are not affected because the endpoint is unreachable and the cloud storage architecture neutralizes the write primitive.

Critical Impact

Authenticated attackers can write arbitrary files to the server filesystem, leading to remote code execution and full service takeover.

Affected Products

  • Altium Enterprise Server (on-premises) Vault Service
  • UploadController image upload endpoint
  • Altium 365 cloud deployments are NOT affected

Discovery Timeline

  • 2026-06-05 - CVE-2026-11419 published to the National Vulnerability Database (NVD)
  • 2026-06-05 - Last updated in NVD database

Technical Details for CVE-2026-11419

Vulnerability Analysis

The Altium Enterprise Server Vault Service exposes an image upload endpoint handled by the UploadController. The controller accepts a path component from authenticated clients and joins it with the service's configured storage root before writing the uploaded content.

The join operation does not normalize or constrain the user-supplied value. When the supplied path is absolute, standard path-joining behavior in many runtimes discards the prior root and uses the attacker-controlled absolute path instead. The upload is then written to that location with the privileges of the service account.

Because the attacker controls both the destination and the file contents, the primitive supports overwriting binaries, dropping web shells into web-accessible directories, or replacing configuration files consumed at startup. Each path leads to remote code execution or service takeover.

Root Cause

The root cause is improper validation of a path component supplied through the upload request [CWE-22]. The controller fails to reject absolute paths, traversal sequences, and paths that resolve outside the configured storage root. No canonicalization or boundary check is performed before the write.

Attack Vector

Exploitation requires authenticated access over the network and low complexity. The attacker sends an image upload request to the Vault Service with a crafted absolute path. The service writes attacker-controlled content to the chosen filesystem location, restricted only by the permissions of the service account.

// No verified public proof-of-concept code is available.
// The vulnerability is triggered by supplying a crafted absolute
// path in the image upload request handled by UploadController,
// causing the configured storage root to be discarded.
// Refer to the Altium Security Advisory for technical details.

Detection Methods for CVE-2026-11419

Indicators of Compromise

  • Files written by the Vault Service account outside the configured storage root, especially in web roots, binary directories, or configuration paths
  • Image upload requests to the UploadController containing absolute paths, drive letters, or .. traversal sequences
  • Unexpected new files in directories such as wwwroot, service install paths, or startup script locations created during a Vault Service session
  • Modified timestamps on existing application binaries or configuration files of the Vault Service

Detection Strategies

  • Inspect Vault Service HTTP logs for upload requests where the path parameter begins with a drive letter, slash, or contains .. segments
  • Baseline the expected storage root and alert on writes by the Vault Service process to any path outside that root
  • Correlate authenticated session identifiers with anomalous file creation events on the host
  • Review File Integrity Monitoring (FIM) output for changes to Altium binaries, IIS-served content, or configuration files

Monitoring Recommendations

  • Enable verbose request logging on the Enterprise Server and forward to a central log store for retention and search
  • Monitor process-level file write telemetry from the Vault Service account using endpoint detection telemetry
  • Alert on creation of executable, script, or .config files in any directory writable by the service account

How to Mitigate CVE-2026-11419

Immediate Actions Required

  • Apply the vendor-supplied update from the Altium Security Advisory as soon as available
  • Restrict network access to the Enterprise Server Vault Service to trusted administrative networks only
  • Audit accounts with authenticated access and remove unused or shared credentials
  • Review the filesystem for unauthorized files written by the Vault Service account since deployment

Patch Information

Altium has published guidance through the Altium Security Advisory. Administrators of on-premises Enterprise Server installations should consult the advisory for fixed version details and upgrade procedures. Altium 365 cloud customers require no action because the endpoint is not reachable in that deployment model.

Workarounds

  • Run the Vault Service under a least-privilege account with write access limited strictly to the configured storage root
  • Place the Enterprise Server behind a reverse proxy or web application firewall that rejects upload requests containing absolute paths or traversal sequences
  • Apply filesystem ACLs that deny the service account write access to web roots, binary directories, and configuration paths
  • Disable or block the affected upload endpoint at the network layer until the patch is applied
bash
# Example: restrict the Vault Service account from writing outside its storage root on Linux
# Replace <svc_user> and <storage_root> with deployment-specific values
chown -R <svc_user>:<svc_user> <storage_root>
find / -xdev -writable -user <svc_user> ! -path "<storage_root>/*" -print
# Review the output and remove write permissions where the service account does not require them

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePath Traversal

  • Vendor/TechAltium

  • SeverityCRITICAL

  • CVSS Score9.4

  • EPSS Probability0.47%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-22
  • Technical References
  • Altium Security Advisory
  • Related CVEs
  • CVE-2026-11431: Altium Server Path Traversal Vulnerability

  • CVE-2026-11423: Altium Enterprise Server Path Traversal

  • CVE-2026-11420: Altium Enterprise Server Path Traversal

  • CVE-2026-9129: Altium Enterprise Server Path Traversal
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English