CVE-2026-26337: Hyland Alfresco Transform Core
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Affected products
- Hyland Alfresco Transform Core: before 5.3.0 (fixed in 5.3.0); version 5.3.0 only
- Hyland Alfresco Transform Service: before 4.3 (fixed in 4.3)
Published 2026-02-19. Last modified 2026-07-14.