CVE-2026-26339

Severity CVSS v4.0:
CRITICAL
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
19/02/2026
Last modified:
02/03/2026

Description

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:* 5.2.4 (excluding)