VYPR

Alfresco Transform Service

by Hyland

CVEs (3)

  • CVE-2026-26339CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

  • CVE-2026-26338CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

  • CVE-2026-26337HigFeb 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.