CVE-2026-26339: Hyland Alfresco Transformation Service Argument Injection RCE
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26339?
CVE-2026-26339 has been classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2026-26339?
To remediate CVE-2026-26339, users should update the Hyland Alfresco Transformation Service to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-26339?
CVE-2026-26339 affects users of the Hyland Alfresco Transformation Service and any software relying on the affected components.
What type of vulnerability is CVE-2026-26339?
CVE-2026-26339 is classified as an argument injection vulnerability that allows for remote code execution.
Can CVE-2026-26339 be exploited without authentication?
Yes, CVE-2026-26339 can be exploited by unauthenticated attackers, making it particularly dangerous.