CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-26339

Critical · CVSS 9.8

Hyland Alfresco Transformation Service — Argument Injection Remote Code Execution (SSRF/RCE via CWE-918)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-918

Description

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

Search profile — drives PoC discovery

Symbols TransformationServicedocument processingargument injectiontransformalfresco-transformATSLibreOfficeImageMagickpdfrenderertransformRequesttransformContentsourceNodeReftargetNodeRefoptions
Keywords CVE-2026-26339Alfresco Transformation Serviceargument injection RCEHyland Alfresco ATS exploitAlfresco document processing RCEalfresco-transform-core PoCunauthenticated RCE AlfrescoAlfresco SSRF argument injection
Versions: All versions of Hyland Alfresco Transformation Service prior to the patch referenced in the 2026 advisory

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z