CVE-2026-24710
Description
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CFEngine Enterprise Mission Portal before 3.21.8, 3.24.3, 3.27.0 is vulnerable to cross-site scripting (XSS) due to missing input sanitization, requiring authenticated access.
Vulnerability
Northern.tech CFEngine Enterprise Mission Portal contains multiple injection flaws, including cross-site scripting (XSS), due to missing input sanitization and improper output escaping [1]. The vulnerability affects versions 3.26.0, 3.24.2, 3.21.7, and earlier [1]. It requires an authenticated user to trigger the injection, e.g., by visiting a crafted page [1].
Exploitation
An attacker with a valid user account can craft a payload that is not sanitized, often as part of a request. When an administrator or other user visits a page displaying the injected content, the malicious JavaScript executes in their browser [1]. The blog also notes that command injection and blind SQL injection are possible through similar unsanitized inputs, though the XSS vector is the focus of this CVE [1].
Impact
Successful XSS allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking, data exfiltration, or further administrative actions [1]. Other injection types may enable running shell commands on the hub or extracting information via timing-based methods, expanding the compromise beyond browser-level access [1].
Mitigation
Upgrade to CFEngine Enterprise 3.27.0, 3.24.3, 3.21.8, or later to remediate the issue [1]. There is no known workaround; the vendor recommends following the official upgrade documentation [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >=3.21 <3.21.8 || >=3.24 <3.24.3 || <3.27.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/nvdMitigationVendor Advisory
- northern.technvdProduct
News mentions
0No linked articles in our index yet.