Junglewise Threat Intelligence

CVE-2026-26338: Hyland Alfresco Transformation Service SSRF in document processing

CVE-2026-26338 · Severity: critical · CVSS 9.8 · Published 2026-02-19

Vendors: Hyland.

Executive brief

Hyland Alfresco Transformation Service, a component used to convert documents into different formats, contains a security flaw that allows unauthorized individuals to perform Server-Side Request Forgery (SSRF). By exploiting this, an attacker could force the server to make requests to internal systems that are not intended to be accessible from the outside. This could lead to the exposure of sensitive internal data, unauthorized access to internal services, or further disruption of corporate operations.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Hyland Alfresco Transformation Service within its document processing functionality. The flaw allows an unauthenticated remote attacker to send specially crafted requests that the server will then execute, potentially targeting internal network resources or metadata services. The vulnerability affects both the Enterprise version (ATS) and the Community version (Transform Core). Patches have been released in Alfresco Transformation Service version 4.3.0 and Alfresco Community (Transform Core) version 5.3.0.

Affected products

  • Hyland Alfresco Transformation Service (Enterprise) < 4.3.0
  • Hyland Alfresco Community (Transform Core) < 5.3.0

Timeline

  • 2026-02-19: disclosed
  • 2026-02-19: advisory

References