CVE-2026-26337

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*
cpe:2.3:a:hyland:alfresco_transform_core:5.3.0:alpha1:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-19 18:24

Updated : 2026-07-14 16:16


NVD link : CVE-2026-26337

Mitre link : CVE-2026-26337

CVE.ORG link : CVE-2026-26337


JSON object : View

Products Affected

hyland

  • alfresco_transform_core
  • alfresco_transform_service
CWE
CWE-36

Absolute Path Traversal