CVE-2026-24711: Northern.tech Cfengine

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.

Affected products

  • Northern.tech Cfengine: before 3.21.8 (fixed in 3.21.8); from 3.24.0, before 3.24.3 (fixed in 3.24.3); version 3.26.0 only

Published 2026-05-14. Last modified 2026-06-17.