CVE-2026-33552
Description
Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Incorrect access control in Mender Enterprise Server before 4.1.1 allows path traversal attacks on artifact creation endpoints.
Vulnerability
An incorrect access control vulnerability exists in Northern.tech Mender Enterprise Server versions 4.1.0, 4.0.1, and earlier (fixed in 4.1.1 and 4.0.2). The bug is due to improper input sanitization in the endpoint for creating artifacts (used from the UI or API), allowing path traversal sequences like ../ to access and modify files outside the intended directory [1].
Exploitation
To exploit this vulnerability, an attacker needs a user account with permissions to access the artifact creation API. In a multi-tenant hosted Mender environment, an attacker can easily sign up for an account with the required permissions. The victim must be using the artifact creation feature. The attacker sends a crafted request containing path traversal sequences to inject arbitrary code into the artifacts being created [1].
Impact
Successful exploitation allows the attacker to compromise the container for other users of the same API, potentially injecting malicious code into artifacts. If cryptographically signed artifacts are used and the Mender client is configured to verify signatures, the device would refuse to install tampered artifacts, mitigating the impact. For on-premise installations with fewer users, the risk is lower as self-signup is typically not possible [1].
Mitigation
This issue is fixed in Mender Server versions 4.1.1 and 4.0.2. Hosted Mender has already been patched. Users on affected versions should upgrade immediately. As a workaround, enable cryptographic artifact signing and client-side signature verification to prevent installation of modified artifacts. If not using the artifact creation feature, the system is not affected [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <4.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.