CVE-2026-26339Disclosure(hyland / alfresco_transform_core)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hyland alfresco_transform_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • alfresco_transform_core
  • alfresco_transform_service

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
alfresco_transform_corealfresco_transform_service

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-19: 3Mentions · 2026-02-20: 1Mentions · 2026-03-22: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 3Technical Details · 2026-02-20: 1Technical Details · 2026-03-22: 102-1902-2003-22
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-193
Disclosure2Patch1
2026-02-201
Disclosure1
2026-03-221
Disclosure1
Full discourse5 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-26339 (CVSS 9.3): Hyland Alfresco Transformation Service argument injection → unauth RCE in doc-processing backend. Content platforms at risk. https://nvd.nist.gov/vuln/detail/CVE-2026-26339

    Post summary

    A newly disclosed, high–severity CVE (CVE-2026-26339) affecting Hyland Alfresco Transformation Service introduces unauthenticated RCE via argument injection in its document‑processing backend.

    0202061
    374 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26339 Unauthenticated Remote Code Execution in Hyland Alfresco Transfor... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26339 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-26339, revealing an unauthenticated remote code execution vulnerability in Hyland Alfresco Transfer, with no additional details on patches, exploits, or active use.

    0001042
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26339: CRITICAL] Beware: Hyland Alfresco Transformation Service vulnerable to argument injection, could enable remote code execution by unauthenticated attackers. #cybersecurity#cve,CVE-2026-26339,#cybersecurity https://cvefind.com/CVE-2026-26339

    Post summary

    The tweet announces a critical CVE (CVE-2026-26339) in Hyland Alfresco Transformation Service, highlighting an argument injection flaw that could allow remote code execution by unauthenticated attackers. No PoC, exploit, patch, or active exploitation evidence is presented.

    0000035
    578 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26339** pertains to the Hyland Alfresco Transformation Service, a component responsible for processing and transforming documents within the Alfresco platform. The vulnerability arises from an **argument injection flaw** in the document processing functionality, which allows **unauthenticated attackers** to execute arbitrary code remotely. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-26339

    Post summary

    The post announces a newly disclosed Hyland Alfresco Transformation Service vulnerability that allows unauthenticated remote code execution via argument injection, but provides no PoC, exploit, or mitigation details.

    0000040
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Unauthenticated RCE risk in Hyland Alfresco Transformation Service! SSRF flaw lets attackers take full control. Patch ASAP & limit service exposure. https://radar.offseq.com/threat/cve-2026-26339-cwe-918-server-side-request-forgery-f1de4ab8 #OffSeq #Vulnerability #... https://t.co/fJeCuNZdO3

    Post summary

    The tweet announces a critical SSRF flaw in Hyland Alfresco Transformation Service that allows unauthenticated RCE and urges immediate patching and service restrictions.

    0000046
    265 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphylandalfresco_transform_core---
Apphylandalfresco_transform_service---

Explore more