Critical severity9.8NVD Advisory· Published Feb 19, 2026· Updated Jul 14, 2026
CVE-2026-26338
CVE-2026-26338
Description
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: 0
- cpe:2.3:a:hyland:alfresco_transform_service:*:*:*:*:*:*:*:*Range: <4.3
cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hyland:alfresco_transform_core:*:*:*:*:*:*:*:*range: <5.3.0
- cpe:2.3:a:hyland:alfresco_transform_core:5.3.0:alpha1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.