CVE-2026-26339

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*

History

02 Mar 2026, 22:07

Type Values Removed Values Added
First Time Hyland alfresco Transform Service
Hyland alfresco Transform Core
CPE cpe:2.3:a:hyland:alfresco_transformation_service:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:*
cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*
cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

28 Feb 2026, 00:00

Type Values Removed Values Added
CPE cpe:2.3:a:hyland:alfresco_transformation_service:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hyland:transform_core_aio:*:*:*:*:community:*:*:*
First Time Hyland transform Core Aio
Hyland
Hyland alfresco Transformation Service
References () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 - () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 - Vendor Advisory
References () https://www.hyland.com/en/solutions/products/alfresco-platform - () https://www.hyland.com/en/solutions/products/alfresco-platform - Product
References () https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce - () https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce - Third Party Advisory
Summary
  • (es) Hyland Alfresco Transformation Service permite a atacantes no autenticados lograr ejecución remota de código a través de la vulnerabilidad de inyección de argumentos, que existe en la funcionalidad de procesamiento de documentos.

20 Feb 2026, 15:20

Type Values Removed Values Added
References
  • () https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551 -

19 Feb 2026, 18:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 18:25

Updated : 2026-03-02 22:07


NVD link : CVE-2026-26339

Mitre link : CVE-2026-26339

CVE.ORG link : CVE-2026-26339


JSON object : View

Products Affected

hyland

  • alfresco_transform_core
  • alfresco_transform_service
CWE
CWE-918

Server-Side Request Forgery (SSRF)