CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-26339

CVSS 9.3v4.0pub. 2026-02-19upd. 2026-03-02

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

🤖 AI Analysis
How it works

The vulnerability (CWE-918 / argument injection) occurs in the module responsible for document processing. An attacker can submit a crafted request to the service without needing to possess any credentials by injecting malicious arguments into process calls or system commands executed during document transformation. As a result, arbitrary code execution in the context of the service process is possible.

Impact

An unauthenticated attacker can take full control of the system on which the service is running — gaining the ability to read and modify data as well as disrupt system operations. The compromise affects only the directly vulnerable component (SC:N in the CVSS vector).

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references — detailed information about versions containing fixes was published in the official Hyland security bulletin at the address indicated in the references (connect.hyland.com).

Who is affected

Hyland Alfresco Transform Service and Hyland Alfresco Transform Core — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hyland Alfresco Transform Core

    APP
    Hyland
    < 5.2.4
  • Hyland Alfresco Transform Service

    APP
    Hyland
    < 4.2.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2026-26337HIGH8.8same product

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read an...

CVE-2026-26338MEDIUM6.9same product

Hyland Alfresco Transformation Service umożliwia nieuwierzytelnionym atakującym przeprowadzenie SSRF poprzez f...

CVE-2026-58126CRITICAL9.3PL ✓same vendor

PACSgear PACS Scan 5.2.1 — nieuwierzytelniony RCE przez .NET Remoting

CVE-2026-58127CRITICAL9.3PL ✓same vendor

PACSgear MediaWriter — nieuwierzytelniony RCE przez .NET Remoting TCP

CVE-2020-25253CRITICAL9.8PL ✓same vendor

SQL Injection w Hyland OnBase — krytyczna podatność wielu wersji