CVE-2026-26337: Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26337?
CVE-2026-26337 is considered a high severity vulnerability due to its potential for unauthorized file access and server-side request forgery.
How do I fix CVE-2026-26337?
To fix CVE-2026-26337, update Hyland Alfresco Transformation Service to the latest version that addresses this vulnerability.
What types of attacks are possible with CVE-2026-26337?
CVEs-2026-26337 can be exploited to perform arbitrary file reads and server-side request forgery (SSRF) attacks.
Which versions of Hyland Alfresco Transformation Service are affected by CVE-2026-26337?
CVE-2026-26337 affects versions of Hyland Alfresco Transformation Service prior to 4.3 and certain versions of Hyland Alfresco Transform Core.
Is authentication required to exploit CVE-2026-26337?
No, exploitation of CVE-2026-26337 does not require authentication, making it accessible to unauthenticated attackers.