Junglewise Threat Intelligence

CVE-2026-26339: Hyland Alfresco Transformation Service argument injection RCE

CVE-2026-26339 · Severity: critical · CVSS 9.8 · Published 2026-02-19

Vendors: Hyland.

Executive brief

Hyland Alfresco Transformation Service, a component used to convert and process documents within the Alfresco content management platform, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to remotely take control of the server. This could lead to a total compromise of the system, including unauthorized access to sensitive documents, data theft, or disruption of business operations.

Technical details

An argument injection vulnerability exists in the document processing functionality of Hyland Alfresco Transformation Service. The flaw allows a remote, unauthenticated attacker to inject malicious arguments into system commands executed by the service during file transformations. By sending a specially crafted request over the network, an attacker can achieve full remote code execution (RCE) on the underlying host. The vulnerability affects both the Enterprise Transformation Service (versions prior to 4.2.3) and the Community Transform Core (versions prior to 5.2.4). While the advisory also references CWE-918 (SSRF), the primary impact is documented as RCE.

Affected products

  • Hyland Alfresco Transformation Service (Enterprise) < 4.2.3
  • Hyland Alfresco Community (Transform Core) < 5.2.4

Timeline

  • 2026-02-19: disclosed: Initial publication of the vulnerability details.
  • 2026-02-19: advisory: Vendor advisory published by Hyland.

References

Related threats