CVE-2026-26339
Last modified
CVE-2026-26339 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hyland | Alfresco Transform Service | < 4.2.3 |
| Hyland | Alfresco Transform Core | < 5.2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-26339?
How severe is CVE-2026-26339?
How do I fix CVE-2026-26339?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26333Calero VeraSMART versions prior to 2022 R1 expose an unauthe…9.8
- CVE-2026-26334Calero VeraSMART versions prior to 2026 R1 contain hardcoded…7.8
- CVE-2026-26335Calero VeraSMART versions prior to 2022 R1 use static ASP.NE…9.8
- CVE-2026-26336Hyland Alfresco allows unauthenticated attackers to read arb…8.7
- CVE-2026-26337Hyland Alfresco Transformation Service allows unauthenticate…8.8
- CVE-2026-26338Hyland Alfresco Transformation Service allows unauthenticate…9.8
- CVE-2026-2634Malicious scripts could cause desynchronization between the …9.8
- CVE-2026-26340Tattile Smart+, Vega, and Basic device families firmware ver…7.5
- CVE-2026-26341Tattile Smart+, Vega, and Basic device families firmware ver…9.8
- CVE-2026-26342Tattile Smart+, Vega, and Basic device families firmware ver…9.8
- CVE-2026-26345SPIP before 4.4.8 contains a stored cross-site scripting (XS…8.6
- CVE-2026-26348Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-26339?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
