CVE-2026-24710

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:3.26.0:*:*:*:enterprise:*:*:*

History

19 May 2026, 16:45

Type Values Removed Values Added
First Time Northern.tech
Northern.tech cfengine
CPE cpe:2.3:a:northern.tech:cfengine:3.26.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
References () https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/ - () https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/ - Mitigation, Vendor Advisory
References () https://northern.tech - () https://northern.tech - Product

14 May 2026, 16:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

14 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 15:16

Updated : 2026-05-19 16:45


NVD link : CVE-2026-24710

Mitre link : CVE-2026-24710

CVE.ORG link : CVE-2026-24710


JSON object : View

Products Affected

northern.tech

  • cfengine
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')