Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
References
Configurations
History
02 Mar 2026, 22:07
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hyland alfresco Transform Service
Hyland alfresco Transform Core |
|
| CPE | cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:* |
cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:* cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:* |
28 Feb 2026, 00:00
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hyland:alfresco_transformation_service:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:* |
|
| First Time |
Hyland transform Core Aio
Hyland Hyland alfresco Transformation Service |
|
| References | () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 - Vendor Advisory | |
| References | () https://www.hyland.com/en/solutions/products/alfresco-platform - Product | |
| References | () https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce - Third Party Advisory | |
| Summary |
|
20 Feb 2026, 15:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Feb 2026, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 18:25
Updated : 2026-03-02 22:07
NVD link : CVE-2026-26339
Mitre link : CVE-2026-26339
CVE.ORG link : CVE-2026-26339
JSON object : View
Products Affected
hyland
- alfresco_transform_core
- alfresco_transform_service
CWE
CWE-918
Server-Side Request Forgery (SSRF)
