TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-26221

N/A

Description

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.

Details CVE

Score CVSS v3.1N/A
Publie2/13/2026
Derniere modification2/13/2026
Sourcenvd
Observations honeypot0

This product uses data from the NVD API but is not endorsed or certified by the NVD.