CVE-2026-26339
Critical · CVSS 9.8Hyland Alfresco Transformation Service — Argument Injection Remote Code Execution (SSRF/RCE via CWE-918)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-918
Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Search profile — drives PoC discovery
Symbols TransformationServicedocument processingargument injectiontransformalfresco-transformATSLibreOfficeImageMagickpdfrenderertransformRequesttransformContentsourceNodeReftargetNodeRefoptions
Keywords CVE-2026-26339Alfresco Transformation Serviceargument injection RCEHyland Alfresco ATS exploitAlfresco document processing RCEalfresco-transform-core PoCunauthenticated RCE AlfrescoAlfresco SSRF argument injection
Versions: All versions of Hyland Alfresco Transformation Service prior to the patch referenced in the 2026 advisory
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z