Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 4.3.0
Any version before 5.3.0
Credits
Piotr Bazydlo (@chudyPB) of watchTowr
References
connect.hyland.com/...-2026-26338-cve-2026-26339/ba-p/496551
www.hyland.com/en/solutions/products/alfresco-platform
www.vulncheck.com/...nd-alfresco-transformation-service-ssrf