CVE-2026-26336
EUVD-2026-837819.02.2026, 17:24
Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hyland | alfresco_content_services | 𝑥 < 25.3 |
| hyland | alfresco_content_services | 7.4.0 ≤ 𝑥 ≤ 7.4.2.5 |
| hyland | alfresco_content_services | 23.1 ≤ 𝑥 ≤ 23.6.0 |
| hyland | alfresco_content_services | 25.1 ≤ 𝑥 ≤ 25.2 |
𝑥
= Vulnerable software versions