CVE-2025-27379: Altium On-Prem Enterprise Server

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content.

Affected products

  • Altium On-Prem Enterprise Server: from 7.0.3, before 7.0.6 (fixed in 7.0.6)

Published 2026-01-22. Last modified 2026-06-17.