CVE-2026-26337
Received
Received - Intake
Path Traversal in Hyland Alfresco Service Enables File Read, SSRF
Publication date: 2026-02-19
Last updated on: 2026-03-02
Assigner: VulnCheck
Description
Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hyland | alfresco_transform_service | to 4.3 (exc) |
| hyland | alfresco_transform_core | to 5.3.0 (exc) |
| hyland | alfresco_transform_core | 5.3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-36 | The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory. |