Executive brief
Hyland Alfresco Transformation Service, a component used to convert documents between different formats, contains a security flaw that allows unauthorized individuals to access sensitive files. By exploiting this vulnerability, an attacker could read internal system files or use the server to launch further attacks against other internal systems. This could lead to the exposure of confidential business data or provide a foothold for deeper network penetration.
Technical details
An absolute path traversal vulnerability (CWE-36) exists in Hyland Alfresco Transformation Service and Alfresco Community (Transform Core). The flaw allows a remote, unauthenticated attacker to bypass path validation logic by providing absolute file paths to the service. This can be leveraged to perform arbitrary file reads from the underlying host or initiate Server-Side Request Forgery (SSRF) attacks. The vulnerability is addressed in Alfresco Transformation Service (Enterprise) version 4.3.0 and Alfresco Community (Transform Core) version 5.3.0.
Affected products
- Hyland Alfresco Transformation Service (Enterprise) < 4.3.0
- Hyland Alfresco Community (Transform Core) < 5.3.0
Timeline
- 2026-02-19: disclosed
- 2026-02-19: advisory
References
- https://connect.hyland.com/t5/alfresco-blog/security-update-cve-2026-26337-cve-2026-26338-cve-2026-26339/ba-p/496551
- https://www.hyland.com/en/solutions/products/alfresco-platform
- https://www.vulncheck.com/advisories/hyland-alfresco-transformation-service-absolute-path-traversal-arbitrary-file-read-and-ssrf