PatchSiren cyber security CVE debrief
CVE-2026-24712 Northern.tech CVE debrief
A command injection vulnerability in Northern.tech CFEngine Enterprise and Community allows unauthenticated remote attackers to execute arbitrary commands on affected systems. The vulnerability stems from improper neutralization of special elements used in OS commands (CWE-77). Affected versions include all Enterprise and Community editions prior to 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. The vulnerability was published on May 14, 2026, with the NVD record last modified on May 19, 2026. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Vendor
- Northern.tech
- Product
- Cfengine
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
System administrators managing CFEngine deployments, security teams responsible for configuration management infrastructure, DevOps engineers utilizing CFEngine for infrastructure automation, and organizations relying on CFEngine for compliance and policy enforcement across their environments.
Technical summary
CVE-2026-24712 is a command injection vulnerability (CWE-77) in Northern.tech CFEngine Enterprise and Community editions. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary OS commands due to improper input sanitization. The CVSS 3.1 base score of 7.3 reflects network accessibility, low attack complexity, and no required privileges or user interaction, with impacts to confidentiality, integrity, and availability all rated as LOW. Affected versions span multiple release branches: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Remediation requires upgrading to patched versions 3.21.8, 3.24.3, 3.27.0, or later.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade CFEngine Enterprise or Community to version 3.21.8, 3.24.3, 3.27.0, or later to remediate this vulnerability
- Review CFEngine policy configurations for unauthorized modifications if running affected versions
- Monitor system logs for anomalous command execution patterns
- Apply principle of least privilege to CFEngine agent execution contexts
- Subscribe to Northern.tech security advisories for future vulnerability notifications
Evidence notes
CVSS 3.1 score of 7.3 (HIGH) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L indicates network-accessible attack vector with low attack complexity, no privileges required, and no user interaction needed. The vulnerability is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command). CPE criteria confirm affected versions across multiple CFEngine release branches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24712 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24712
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24712 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24712
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/
[email protected] - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://northern.tech/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.