CVE-2026-24712
CFEngine vulnerability analysis and mitigation

Overview

CVE-2026-24712 is a command injection vulnerability affecting Northern.tech CFEngine Enterprise and Community editions. It allows network-based attackers to execute arbitrary commands without authentication or user interaction. Affected versions include all releases before 3.21.8, 3.24.3, and 3.27.0 (including the 3.24.x and 3.26.0 branches). The vulnerability was published on May 14, 2026, with a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, CFEngine Blog).

Technical details

The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command), meaning CFEngine fails to properly sanitize externally-influenced input before incorporating it into system commands. The attack vector is network-accessible, requires no privileges, no user interaction, and low attack complexity, making it straightforward to exploit remotely. Specific vulnerable components or endpoints have not been publicly detailed beyond the vendor advisory, but the flaw is present in both the Enterprise and Community editions across multiple release branches (GitHub Advisory, CFEngine Blog).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands on systems running vulnerable CFEngine instances, resulting in low-to-moderate impacts on confidentiality, integrity, and availability. Because CFEngine is a configuration management and automation platform typically deployed across large infrastructure fleets, compromise of a CFEngine hub or agent could facilitate lateral movement to managed nodes. Data exposure, unauthorized configuration changes, and disruption of automated policy enforcement are all plausible consequences (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 1.27% (Feedly data) to 0.374% (GitHub Advisory), placing it in roughly the 59th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been made (GitHub Advisory).

Mitigation and workarounds

Northern.tech has released patched versions addressing this vulnerability: 3.21.8, 3.24.3, and 3.27.0. Organizations running CFEngine Enterprise or Community should upgrade to one of these fixed releases immediately. The vendor advisory covering this CVE alongside related issues CVE-2026-24710 and CVE-2026-24711 is available on the CFEngine blog and should be consulted for any additional guidance or workarounds (CFEngine Blog, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related CFEngine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-45684HIGH7.5
  • CFEngine logoCFEngine
  • cfengine3
NoYesNov 14, 2023
CVE-2026-24712HIGH7.3
  • CFEngine logoCFEngine
  • cfengine3
NoYesMay 14, 2026
CVE-2023-26560MEDIUM6.5
  • CFEngine logoCFEngine
  • cfengine
NoYesApr 26, 2023
CVE-2026-24710MEDIUM6.1
  • CFEngine logoCFEngine
  • cfengine
NoYesMay 14, 2026
CVE-2026-24711MEDIUM5.3
  • CFEngine logoCFEngine
  • cfengine
NoYesMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management