Hyland Alfresco Improper Authorization Arbitrary File Read Vulnerability

Vulnerability

A vulnerability in Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories, such as WEB-INF, through the '/share/page/resource/' endpoint. This file read access can lead to the disclosure of sensitive configuration files.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive files, including configuration files that may contain critical application or server information.

Added: Feb 19, 2026, 6:17 PM
Updated: Feb 19, 2026, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
3.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.