CVE-2026-26336: Hyland Alfresco Content Services

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.

Affected products

  • Hyland Alfresco Content Services: before 25.3 (fixed in 25.3); from 7.4.0, up to and including 7.4.2.5; from 23.1, up to and including 23.6.0; from 25.1, up to and including 25.2

Published 2026-02-19. Last modified 2026-06-17.