
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24710 is a Cross-Site Scripting (XSS) vulnerability in Northern.tech CFEngine Enterprise that allows attackers to inject malicious scripts via unvalidated input. It affects CFEngine Enterprise versions before 3.21.8, versions 3.24.0 through 3.24.2 (before 3.24.3), and version 3.26.0 (before 3.27.0). The vulnerability was published on May 14, 2026, with patches released in versions 3.21.8, 3.24.3, and 3.27.0. It carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, CFEngine Blog).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), meaning CFEngine Enterprise fails to properly sanitize or encode user-controllable input before rendering it in web pages served to other users. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a victim clicking a crafted link or visiting a malicious page), and results in a changed scope affecting components beyond the vulnerable application. The specific injection point and XSS type (reflected, stored, or DOM-based) have not been publicly detailed beyond the vendor advisory (GitHub Advisory, CFEngine Blog).
Successful exploitation could allow an attacker to steal session tokens, hijack authenticated user sessions, or execute arbitrary actions within the CFEngine Enterprise web interface on behalf of a victim user. Given that CFEngine Enterprise is an infrastructure automation and configuration management platform, session hijacking could expose sensitive configuration data, policy definitions, and system inventory information. Confidentiality and integrity impacts are rated low, and there is no direct availability impact (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-24710. The EPSS score is approximately 0.029–0.038%, placing it in the 12th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (GitHub Advisory).
Northern.tech has released patched versions of CFEngine Enterprise: 3.21.8, 3.24.3, and 3.27.0. Organizations running any version prior to these should upgrade immediately. No specific configuration-based workarounds have been publicly documented; upgrading to a fixed version is the recommended remediation (CFEngine Blog, GitHub Advisory).
Northern.tech published a blog post addressing CVE-2026-24710 alongside two related CVEs (CVE-2026-24711 and CVE-2026-24712), indicating a coordinated disclosure of multiple vulnerabilities in the same release cycle. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (CFEngine Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."