CVE-2026-26338

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*
cpe:2.3:a:hyland:alfresco_transform_core:5.3.0:alpha1:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-19 18:24

Updated : 2026-03-02 22:03


NVD link : CVE-2026-26338

Mitre link : CVE-2026-26338

CVE.ORG link : CVE-2026-26338


JSON object : View

Products Affected

hyland

  • alfresco_transform_service
  • alfresco_transform_core
CWE
CWE-918

Server-Side Request Forgery (SSRF)