CVE-2026-26339: Hyland Alfresco Transform Core

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

Affected products

  • Hyland Alfresco Transform Core: before 5.2.4 (fixed in 5.2.4)
  • Hyland Alfresco Transform Service: before 4.2.3 (fixed in 4.2.3)

Published 2026-02-19. Last modified 2026-07-14.