Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Problem types
CWE-36 Absolute Path Traversal
Product status
Any version before 4.3.0
Any version before 5.3.0
Credits
Piotr Bazydlo (@chudyPB) of watchTowr
References
connect.hyland.com/...-2026-26338-cve-2026-26339/ba-p/496551
www.hyland.com/en/solutions/products/alfresco-platform
www.vulncheck.com/...-traversal-arbitrary-file-read-and-ssrf