CVE-2026-24710
CFEngine vulnerability analysis and mitigation

Overview

CVE-2026-24710 is a Cross-Site Scripting (XSS) vulnerability in Northern.tech CFEngine Enterprise that allows attackers to inject malicious scripts via unvalidated input. It affects CFEngine Enterprise versions before 3.21.8, versions 3.24.0 through 3.24.2 (before 3.24.3), and version 3.26.0 (before 3.27.0). The vulnerability was published on May 14, 2026, with patches released in versions 3.21.8, 3.24.3, and 3.27.0. It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, CFEngine Blog).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), meaning CFEngine Enterprise fails to properly sanitize or encode user-controllable input before rendering it in web pages served to other users. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a victim clicking a crafted link or visiting a malicious page), and results in a changed scope affecting components beyond the vulnerable application. The specific injection point and XSS type (reflected, stored, or DOM-based) have not been publicly detailed beyond the vendor advisory (GitHub Advisory, CFEngine Blog).

Impact

Successful exploitation could allow an attacker to steal session tokens, hijack authenticated user sessions, or execute arbitrary actions within the CFEngine Enterprise web interface on behalf of a victim user. Given that CFEngine Enterprise is an infrastructure automation and configuration management platform, session hijacking could expose sensitive configuration data, policy definitions, and system inventory information. Confidentiality and integrity impacts are rated low, and there is no direct availability impact (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-24710. The EPSS score is approximately 0.029–0.038%, placing it in the 12th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (GitHub Advisory).

Mitigation and workarounds

Northern.tech has released patched versions of CFEngine Enterprise: 3.21.8, 3.24.3, and 3.27.0. Organizations running any version prior to these should upgrade immediately. No specific configuration-based workarounds have been publicly documented; upgrading to a fixed version is the recommended remediation (CFEngine Blog, GitHub Advisory).

Community reactions

Northern.tech published a blog post addressing CVE-2026-24710 alongside two related CVEs (CVE-2026-24711 and CVE-2026-24712), indicating a coordinated disclosure of multiple vulnerabilities in the same release cycle. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (CFEngine Blog).

Additional resources


SourceThis report was generated using AI

Related CFEngine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-45684HIGH7.5
  • CFEngine logoCFEngine
  • cfengine3
NoYesNov 14, 2023
CVE-2026-24712HIGH7.3
  • CFEngine logoCFEngine
  • cfengine3
NoYesMay 14, 2026
CVE-2023-26560MEDIUM6.5
  • CFEngine logoCFEngine
  • cfengine
NoYesApr 26, 2023
CVE-2026-24710MEDIUM6.1
  • CFEngine logoCFEngine
  • cfengine
NoYesMay 14, 2026
CVE-2026-24711MEDIUM5.3
  • CFEngine logoCFEngine
  • cfengine
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management