CVE-2026-26339

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*

History

02 Mar 2026, 22:07

Type Values Removed Values Added
First Time Hyland alfresco Transform Service
Hyland alfresco Transform Core
CPE cpe:2.3:a:hyland:alfresco_transformation_service:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:*
cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*
cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

28 Feb 2026, 00:00

Type Values Removed Values Added
References () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 - () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 - Vendor Advisory
References () https://www.hyland.com/en/solutions/products/alfresco-platform - () https://www.hyland.com/en/solutions/products/alfresco-platform - Product
References () https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce - () https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce - Third Party Advisory
CPE cpe:2.3:a:hyland:alfresco_transformation_service:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:*
Summary
  • (es) Hyland Alfresco Transformation Service permite a atacantes no autenticados lograr ejecución remota de código a través de la vulnerabilidad de inyección de argumentos, que existe en la funcionalidad de procesamiento de documentos.
First Time Hyland transform Core Aio
Hyland
Hyland alfresco Transformation Service

20 Feb 2026, 15:20

Type Values Removed Values Added
References
  • () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 -

19 Feb 2026, 18:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 18:25

Updated : 2026-03-02 22:07


NVD link : CVE-2026-26339

Mitre link : CVE-2026-26339

CVE.ORG link : CVE-2026-26339


JSON object : View

Products Affected

hyland

  • alfresco_transform_core
  • alfresco_transform_service
CWE
CWE-918

Server-Side Request Forgery (SSRF)