CVE-2026-26221: Hyland OnBase Timer Service Unauthenticated .NET Remoting RCE

Published Feb 13, 2026
·
Updated

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.

Affected Software

1 affected component
Hyland OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe)

Event History

Feb 13, 2026
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Mar 12, 58253
Event
via NVD·11:00 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-26221?

CVE-2026-26221 is classified as a critical vulnerability due to its potential for remote code execution.

2

What does CVE-2026-26221 affect?

CVE-2026-26221 affects Hyland OnBase, specifically the Workflow Timer Service and possibly the Workview Timer Service.

3

How do I fix CVE-2026-26221?

To fix CVE-2026-26221, it is recommended to update to the latest version of Hyland OnBase that addresses this vulnerability.

4

Can CVE-2026-26221 be exploited without authentication?

Yes, CVE-2026-26221 can be exploited without authentication, allowing attackers to potentially execute arbitrary code.

5

What are the potential impacts of CVE-2026-26221?

The potential impacts of CVE-2026-26221 include unauthorized remote code execution, which can lead to data breaches and system compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203