PatchSiren cyber security CVE debrief
CVE-2026-24712 Northern.tech CVE debrief
A command injection vulnerability in Northern.tech CFEngine Enterprise and Community allows unauthenticated remote attackers to execute arbitrary commands on affected systems. The vulnerability stems from improper neutralization of special elements used in OS commands (CWE-77). Affected versions include all Enterprise and Community editions prior to 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. The vulnerability was published on May 14, 2026, with the NVD record last modified on May 19, 2026. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Vendor
- Northern.tech
- Product
- Cfengine
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
System administrators managing CFEngine deployments, security teams responsible for configuration management infrastructure, DevOps engineers utilizing CFEngine for infrastructure automation, and organizations relying on CFEngine for compliance and policy enforcement across their environments.
Technical summary
CVE-2026-24712 is a command injection vulnerability (CWE-77) in Northern.tech CFEngine Enterprise and Community editions. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary OS commands due to improper input sanitization. The CVSS 3.1 base score of 7.3 reflects network accessibility, low attack complexity, and no required privileges or user interaction, with impacts to confidentiality, integrity, and availability all rated as LOW. Affected versions span multiple release branches: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Remediation requires upgrading to patched versions 3.21.8, 3.24.3, 3.27.0, or later.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade CFEngine Enterprise or Community to version 3.21.8, 3.24.3, 3.27.0, or later to remediate this vulnerability
- Review CFEngine policy configurations for unauthorized modifications if running affected versions
- Monitor system logs for anomalous command execution patterns
- Apply principle of least privilege to CFEngine agent execution contexts
- Subscribe to Northern.tech security advisories for future vulnerability notifications
Evidence notes
CVSS 3.1 score of 7.3 (HIGH) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L indicates network-accessible attack vector with low attack complexity, no privileges required, and no user interaction needed. The vulnerability is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command). CPE criteria confirm affected versions across multiple CFEngine release branches.
Official resources
-
CVE-2026-24712 CVE record
CVE.org
-
CVE-2026-24712 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Mitigation, Vendor Advisory
-
Source reference
[email protected] - Product
The vulnerability was disclosed through official channels with vendor advisory and mitigation guidance published by Northern.tech. The CVE was assigned and published on May 14, 2026, with subsequent modifications to the NVD record on May 19