PatchSiren cyber security CVE debrief
CVE-2026-24710 Northern.tech CVE debrief
A cross-site scripting (XSS) vulnerability exists in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. The vulnerability, published on 2026-05-14 and last modified on 2026-05-19, allows attackers to inject malicious scripts into web pages viewed by other users. With a CVSS 3.1 score of 6.1 (MEDIUM severity), the attack vector is network-based with low attack complexity, requiring no privileges but user interaction. The scope is changed, with low impacts to confidentiality and integrity. The weakness is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation).
- Vendor
- Northern.tech
- Product
- CFEngine Enterprise
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations using CFEngine Enterprise for infrastructure configuration management, particularly those with web-exposed management interfaces or multi-user environments where authenticated users may view shared reports or dashboards.
Technical summary
CFEngine Enterprise, a configuration management platform by Northern.tech, contains a reflected or stored XSS vulnerability in its web interface components. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). Affected versions include all releases prior to 3.21.8, the 3.24.x branch before 3.24.3, and version 3.26.0. The vendor has released patched versions and published a security advisory addressing this and two related CVEs.
Defensive priority
medium
Recommended defensive actions
- Upgrade CFEngine Enterprise to version 3.21.8, 3.24.3, or 3.27.0 or later.
- Review vendor security advisory for additional mitigation guidance.
- Implement Content Security Policy (CSP) headers to mitigate XSS impact.
- Validate and sanitize all user inputs in web-facing CFEngine components.
- Monitor for suspicious script injection attempts in CFEngine web interfaces.
Evidence notes
CVE published 2026-05-14; modified 2026-05-19. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. CPE configurations indicate affected versions: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Vendor advisory published at cfengine.com blog.
Official resources
-
CVE-2026-24710 CVE record
CVE.org
-
CVE-2026-24710 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Mitigation, Vendor Advisory
-
Source reference
[email protected] - Product
2026-05-14T15:16:44.710Z