Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 4.2.3
Any version before 5.2.4
Credits
Piotr Bazydlo (@chudyPB) of watchTowr
References
connect.hyland.com/...-2026-26338-cve-2026-26339/ba-p/496551
www.hyland.com/en/solutions/products/alfresco-platform
www.vulncheck.com/...ormation-service-argument-injection-rce