CVE-2026-26338: Hyland Alfresco Transform Core

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

Affected products

  • Hyland Alfresco Transform Core: before 5.3.0 (fixed in 5.3.0); version 5.3.0 only
  • Hyland Alfresco Transform Service: before 4.3 (fixed in 4.3)

Published 2026-02-19. Last modified 2026-07-14.