CVE-2026-26337: Hyland Alfresco Transform Core

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.

Affected products

  • Hyland Alfresco Transform Core: before 5.3.0 (fixed in 5.3.0); version 5.3.0 only
  • Hyland Alfresco Transform Service: before 4.3 (fixed in 4.3)

Published 2026-02-19. Last modified 2026-07-14.