PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24710 Northern.tech CVE debrief

A cross-site scripting (XSS) vulnerability exists in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. The vulnerability, published on 2026-05-14 and last modified on 2026-05-19, allows attackers to inject malicious scripts into web pages viewed by other users. With a CVSS 3.1 score of 6.1 (MEDIUM severity), the attack vector is network-based with low attack complexity, requiring no privileges but user interaction. The scope is changed, with low impacts to confidentiality and integrity. The weakness is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation).

Vendor
Northern.tech
Product
CFEngine Enterprise
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-19
Advisory published
2026-05-14
Advisory updated
2026-05-19

Who should care

Organizations using CFEngine Enterprise for infrastructure configuration management, particularly those with web-exposed management interfaces or multi-user environments where authenticated users may view shared reports or dashboards.

Technical summary

CFEngine Enterprise, a configuration management platform by Northern.tech, contains a reflected or stored XSS vulnerability in its web interface components. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). Affected versions include all releases prior to 3.21.8, the 3.24.x branch before 3.24.3, and version 3.26.0. The vendor has released patched versions and published a security advisory addressing this and two related CVEs.

Defensive priority

medium

Recommended defensive actions

  • Upgrade CFEngine Enterprise to version 3.21.8, 3.24.3, or 3.27.0 or later.
  • Review vendor security advisory for additional mitigation guidance.
  • Implement Content Security Policy (CSP) headers to mitigate XSS impact.
  • Validate and sanitize all user inputs in web-facing CFEngine components.
  • Monitor for suspicious script injection attempts in CFEngine web interfaces.

Evidence notes

CVE published 2026-05-14; modified 2026-05-19. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. CPE configurations indicate affected versions: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Vendor advisory published at cfengine.com blog.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-24710 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-24710

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-24710 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24710

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.