CVE-2026-26221
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.
Published:Feb 13, 2026
Last Modified:May 12, 2026
EPS:Feb 13, 2026
EPSS Score:0.00619
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Hyland
Product
Onbase
Hyland
Onbase
Vendor
Hyland
Product
Onbase Workflow Timer Service
Hyland
Onbase Workflow Timer Service
Vendor
Hyland
Product
Onbase Workview Timer Service
Hyland
Onbase Workview Timer Service
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
