Executive brief
Northern.tech CFEngine Enterprise, a platform used for managing and automating IT infrastructure, is affected by multiple injection vulnerabilities in its Mission Portal interface. An authenticated attacker could use these flaws to execute malicious scripts in the browsers of other users, such as administrators, or potentially run unauthorized commands on the management hub. This could lead to unauthorized access to sensitive infrastructure data or a compromise of the management console.
Technical details
The vulnerability exists due to missing input sanitization and improper output escaping within the Mission Portal component of CFEngine Enterprise. An authenticated attacker with access to the web interface can inject malicious payloads (JavaScript, SQL, or shell commands) through user-input fields. While the primary classification is XSS, the vendor advisory indicates that the same lack of sanitization also allows for blind SQL injection and OS command injection on the hub. Exploitation requires the attacker to have an initial level of access (authenticated user) and, in the case of XSS, requires interaction from another user (e.g., an administrator visiting a compromised page). The issues are resolved in versions 3.21.8, 3.24.3, and 3.27.0.
Affected products
- Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, 3.27.0
Timeline
- 2026-02-09: patched: Vendor released fix and advisory
- 2026-05-14: disclosed: CVE published to NVD