CVE-2026-26336: Hyland Alfresco Improper Authorization Arbitrary File Read
Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26336?
CVE-2026-26336 has been classified as a high severity vulnerability due to its potential for disclosing sensitive information.
How can CVE-2026-26336 be exploited?
CVE-2026-26336 can be exploited by unauthenticated attackers who access the "/share/page/resource/" endpoint to read files from protected directories.
How do I fix CVE-2026-26336?
To fix CVE-2026-26336, implement authentication checks to restrict access to the "/share/page/resource/" endpoint.
What are the consequences of ignoring CVE-2026-26336?
Ignoring CVE-2026-26336 may lead to unauthorized access and exposure of sensitive configuration files.
Which versions of Hyland Alfresco are affected by CVE-2026-26336?
CVE-2026-26336 affects all versions of Hyland Alfresco that allow unauthenticated access to the vulnerable endpoint.