CVE Feed

    Dashboard / CVE / CVE-2026-26221

    CVE-2026-26221

    Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.

    Published:Feb 13, 2026
    Last Modified:May 12, 2026
    EPS:Feb 13, 2026
    EPSS Score:0.00619
    CVSS Score:9.8

    Affected Products

    Vendor
    Hyland
    Product
    Onbase
    Vendor
    Hyland
    Product
    Onbase Workflow Timer Service
    Vendor
    Hyland
    Product
    Onbase Workview Timer Service

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High