CVE-2025-27378: Altium On-Prem Enterprise Server
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries.
Affected products
- Altium On-Prem Enterprise Server: from 7.0.3, before 7.0.6 (fixed in 7.0.6)
Published 2026-01-22. Last modified 2026-06-17.