PatchSiren cyber security CVE debrief
CVE-2026-24710 Northern.tech CVE debrief
A cross-site scripting (XSS) vulnerability exists in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. The vulnerability, published on 2026-05-14 and last modified on 2026-05-19, allows attackers to inject malicious scripts into web pages viewed by other users. With a CVSS 3.1 score of 6.1 (MEDIUM severity), the attack vector is network-based with low attack complexity, requiring no privileges but user interaction. The scope is changed, with low impacts to confidentiality and integrity. The weakness is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation).
- Vendor
- Northern.tech
- Product
- CFEngine Enterprise
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations using CFEngine Enterprise for infrastructure configuration management, particularly those with web-exposed management interfaces or multi-user environments where authenticated users may view shared reports or dashboards.
Technical summary
CFEngine Enterprise, a configuration management platform by Northern.tech, contains a reflected or stored XSS vulnerability in its web interface components. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). Affected versions include all releases prior to 3.21.8, the 3.24.x branch before 3.24.3, and version 3.26.0. The vendor has released patched versions and published a security advisory addressing this and two related CVEs.
Defensive priority
medium
Recommended defensive actions
- Upgrade CFEngine Enterprise to version 3.21.8, 3.24.3, or 3.27.0 or later.
- Review vendor security advisory for additional mitigation guidance.
- Implement Content Security Policy (CSP) headers to mitigate XSS impact.
- Validate and sanitize all user inputs in web-facing CFEngine components.
- Monitor for suspicious script injection attempts in CFEngine web interfaces.
Evidence notes
CVE published 2026-05-14; modified 2026-05-19. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. CPE configurations indicate affected versions: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Vendor advisory published at cfengine.com blog.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24710 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24710
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24710 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24710
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/
[email protected] - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://northern.tech/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.