CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-26338

Critical · CVSS 9.8

Hyland Alfresco Transformation Service — Server-Side Request Forgery (SSRF)

CVSS
9.8
nvd
EPSS
0.36%
28th pct
KEV
No
Class
oss containerizable
CWE-918

Description

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

Search profile — drives PoC discovery

Symbols Alfresco Transformation Servicedocument processingtransformationTransformationServicetransformContenttransformDocumentsourceUrltargetUrltransformalfresco-transform
Keywords CVE-2026-26338Alfresco Transformation Service SSRFHyland Alfresco SSRFalfresco-transform-core SSRFAlfresco document processing SSRFunauthenticated SSRF AlfrescoCWE-918 AlfrescoHyland Alfresco CVE-2026-26338 PoC
Versions: <UNKNOWN>

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z