CVE-2026-26221
Last modified
CVE-2026-26221 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-26221?
How severe is CVE-2026-26221?
How do I fix CVE-2026-26221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26216Crawl4AI versions prior to 0.8.0 contain a remote code execu…10
- CVE-2026-26217Crawl4AI versions prior to 0.8.0 contain a local file inclus…7.5
- CVE-2026-26218newbee-mall includes pre-seeded administrator accounts in it…9.8
- CVE-2026-26219newbee-mall stores and verifies user passwords using an unsa…9.3
- CVE-2026-2622A vulnerability was detected in Blossom up to 1.17.1. This v…5.4
- CVE-2026-26220LightLLM version 1.1.0 and prior contain an unauthenticated …9.3
- CVE-2026-26222Altec DocLink (now maintained by Beyond Limits Inc.) version…9.8
- CVE-2026-26223SPIP before 4.4.8 allows cross-site scripting (XSS) in the p…6.1
- CVE-2026-26224Intego Log Reporter, a macOS diagnostic utility bundled with…8.5
- CVE-2026-26225Intego Personal Backup, a macOS backup utility that allows u…8.5
- CVE-2026-26226beautiful-mermaid versions prior to 0.1.3 contain an SVG att…5.3
- CVE-2026-26227VideoLAN VLC for Android prior to version 3.7.0 contains an …6.3
Are you affected by CVE-2026-26221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
