๐Ÿ” CVE Alert

CVE-2026-26222

UNKNOWN 0.0

DocLink .NET Remoting Unauthenticated Arbitrary File Read/Write RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote attackers to read arbitrary files from the underlying system by specifying local file paths. Additionally, attackers can coerce SMB authentication via UNC paths and write arbitrary files to server locations. Because writable paths may be web-accessible under IIS, this can result in unauthenticated remote code execution or denial of service through file overwrite.

CWE CWE-502 CWE-918
Vendor beyond limits inc.
Product altec doclink
Published Feb 24, 2026
Last Updated Feb 27, 2026
Stay Ahead of the Next One

Get instant alerts for beyond limits inc. altec doclink

Be the first to know when new unknown vulnerabilities affecting beyond limits inc. altec doclink are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Beyond Limits Inc. / Altec DocLink
4.0.336.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
doclinkai.com: https://doclinkai.com/ vulncheck.com: https://www.vulncheck.com/advisories/doclink-net-remoting-unauthenticated-arbitrary-file-read-write-rce

Credits

Victor A. Morales, Senior Pentester Team Leader, GM Sectec, Corp Omar Crespo, Pentester, GM Sectec, Corp