
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24712 is a command injection vulnerability affecting Northern.tech CFEngine Enterprise and Community editions. It allows network-based attackers to execute arbitrary commands without authentication or user interaction. Affected versions include all releases before 3.21.8, 3.24.3, and 3.27.0 (including the 3.24.x and 3.26.0 branches). The vulnerability was published on May 14, 2026, with a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, CFEngine Blog).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command), meaning CFEngine fails to properly sanitize externally-influenced input before incorporating it into system commands. The attack vector is network-accessible, requires no privileges, no user interaction, and low attack complexity, making it straightforward to exploit remotely. Specific vulnerable components or endpoints have not been publicly detailed beyond the vendor advisory, but the flaw is present in both the Enterprise and Community editions across multiple release branches (GitHub Advisory, CFEngine Blog).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary commands on systems running vulnerable CFEngine instances, resulting in low-to-moderate impacts on confidentiality, integrity, and availability. Because CFEngine is a configuration management and automation platform typically deployed across large infrastructure fleets, compromise of a CFEngine hub or agent could facilitate lateral movement to managed nodes. Data exposure, unauthorized configuration changes, and disruption of automated policy enforcement are all plausible consequences (GitHub Advisory).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 1.27% (Feedly data) to 0.374% (GitHub Advisory), placing it in roughly the 59th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been made (GitHub Advisory).
Northern.tech has released patched versions addressing this vulnerability: 3.21.8, 3.24.3, and 3.27.0. Organizations running CFEngine Enterprise or Community should upgrade to one of these fixed releases immediately. The vendor advisory covering this CVE alongside related issues CVE-2026-24710 and CVE-2026-24711 is available on the CFEngine blog and should be consulted for any additional guidance or workarounds (CFEngine Blog, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."