The CVE record is available at: https://www.cve.org/cverecord?id=CVE-2026-26336 .
Using crafted HTTP requests, an attacker can read certain application files located within the Share web application directory. No authentication is required to exploit this issue.
The vulnerability is limited to files within the Share web application directory and does not permit arbitrary filesystem access beyond that scope.
Enterprise (Alfresco Content Services)
Community Edition
Enterprise (Alfresco Content Services)
Community Edition
Upgrade Share by moving to a fixed release listed above (preferred). Customers should apply the appropriate hotfix or upgrade as soon as possible.
Additional recommendations:
Acknowledgment: Thanks to Piotr Bazydło (watchTowr) for responsible disclosure.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.