PT-2026-20876 · Hyland · Alfresco Transformation Service

Chudypb

+1

·

Published

2026-02-19

·

Updated

2026-03-02

·

CVE-2026-26337

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Hyland Alfresco Transformation Service (affected versions not specified)
Description The Hyland Alfresco Transformation Service is susceptible to exploitation allowing unauthenticated attackers to perform arbitrary file read and server-side request forgery (SSRF) through absolute path traversal. The vulnerability allows attackers to access files and potentially manipulate server-side requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-26337

Affected Products

Alfresco Transformation Service