Impact
Hyland Alfresco Transformation Service permits unauthenticated attackers to inject arguments into the document processing function, leading to remote code execution. The vulnerability is classified as argument injection (CWE‑918) and carries a CVSS score of 9.3, indicating a severe risk when exploited.
Affected Systems
The affected products are Hyland's Alfresco Community (Transform Core) and Hyland's Alfresco Transformation Service (Enterprise). No specific version information was supplied, so all deployments of these products may be vulnerable.
Risk and Exploitability
The likelihood of exploitation presently appears low, with an EPSS score of less than 1%. However, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, implying no active exploitation reported at this time. Attackers would likely exploit the service by sending crafted documents or parameters that trigger the injection, granting them the ability to run arbitrary commands without authentication.
OpenCVE Enrichment