CVE-2026-24711

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:3.26.0:*:*:*:enterprise:*:*:*

History

19 May 2026, 16:44

Type Values Removed Values Added
CPE cpe:2.3:a:northern.tech:cfengine:3.26.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
First Time Northern.tech
Northern.tech cfengine
References () https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/ - () https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/ - Mitigation, Vendor Advisory
References () https://northern.tech - () https://northern.tech - Product

15 May 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-284

14 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 15:16

Updated : 2026-05-19 16:44


NVD link : CVE-2026-24711

Mitre link : CVE-2026-24711

CVE.ORG link : CVE-2026-24711


JSON object : View

Products Affected

northern.tech

  • cfengine
CWE
CWE-284

Improper Access Control