Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal. | |
| Title | Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF | |
| Weaknesses | CWE-36 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-19T17:01:25.527Z
Reserved: 2026-02-13T17:28:43.053Z
Link: CVE-2026-26337
No data.
Status : Received
Published: 2026-02-19T18:24:59.730
Modified: 2026-02-19T18:24:59.730
Link: CVE-2026-26337
No data.
OpenCVE Enrichment
No data.
Weaknesses