CVE-2026-26339
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.hyland.com/en/solutions/products/alfresco-platform, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26339.json, https://nvd.nist.gov/vuln/detail/CVE-2026-26339, https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-argument-injection-rce, https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551, https://github.com/Alfresco/alfresco-transform-core