PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24712 Northern.tech CVE debrief

A command injection vulnerability in Northern.tech CFEngine Enterprise and Community allows unauthenticated remote attackers to execute arbitrary commands on affected systems. The vulnerability stems from improper neutralization of special elements used in OS commands (CWE-77). Affected versions include all Enterprise and Community editions prior to 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. The vulnerability was published on May 14, 2026, with the NVD record last modified on May 19, 2026. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Vendor
Northern.tech
Product
Cfengine
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-19
Advisory published
2026-05-14
Advisory updated
2026-05-19

Who should care

System administrators managing CFEngine deployments, security teams responsible for configuration management infrastructure, DevOps engineers utilizing CFEngine for infrastructure automation, and organizations relying on CFEngine for compliance and policy enforcement across their environments.

Technical summary

CVE-2026-24712 is a command injection vulnerability (CWE-77) in Northern.tech CFEngine Enterprise and Community editions. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary OS commands due to improper input sanitization. The CVSS 3.1 base score of 7.3 reflects network accessibility, low attack complexity, and no required privileges or user interaction, with impacts to confidentiality, integrity, and availability all rated as LOW. Affected versions span multiple release branches: all versions before 3.21.8, versions 3.24.0 through 3.24.2, and version 3.26.0. Remediation requires upgrading to patched versions 3.21.8, 3.24.3, 3.27.0, or later.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade CFEngine Enterprise or Community to version 3.21.8, 3.24.3, 3.27.0, or later to remediate this vulnerability
  • Review CFEngine policy configurations for unauthorized modifications if running affected versions
  • Monitor system logs for anomalous command execution patterns
  • Apply principle of least privilege to CFEngine agent execution contexts
  • Subscribe to Northern.tech security advisories for future vulnerability notifications

Evidence notes

CVSS 3.1 score of 7.3 (HIGH) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L indicates network-accessible attack vector with low attack complexity, no privileges required, and no user interaction needed. The vulnerability is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command). CPE criteria confirm affected versions across multiple CFEngine release branches.

Official resources

The vulnerability was disclosed through official channels with vendor advisory and mitigation guidance published by Northern.tech. The CVE was assigned and published on May 14, 2026, with subsequent modifications to the NVD record on May 19