CVE-2026-26338
Critical · CVSS 9.8Hyland Alfresco Transformation Service — Server-Side Request Forgery (SSRF)
- CVSS
- 9.8
- nvd
- EPSS
- 0.36%
- 28th pct
- KEV
- No
- Class
- oss containerizable
- CWE-918
Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.
Search profile — drives PoC discovery
Symbols Alfresco Transformation Servicedocument processingtransformationTransformationServicetransformContenttransformDocumentsourceUrltargetUrltransformalfresco-transform
Keywords CVE-2026-26338Alfresco Transformation Service SSRFHyland Alfresco SSRFalfresco-transform-core SSRFAlfresco document processing SSRFunauthenticated SSRF AlfrescoCWE-918 AlfrescoHyland Alfresco CVE-2026-26338 PoC
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z