Executive brief
Northern.tech CFEngine Enterprise, a platform used to manage and automate large-scale IT infrastructure, contains a security flaw in its Mission Portal management interface. An attacker with a low-privileged user account can bypass security controls to access restricted information or escalate their permissions to administrative levels. If successful, an attacker could gain full control over the management hub and all connected devices in the corporate infrastructure.
Technical details
A broken access control vulnerability exists in the Mission Portal component of CFEngine Enterprise. The flaw allows an authenticated user with low-level privileges to bypass authorization checks. By exploiting this issue, an attacker can access sensitive information beyond their assigned scope or escalate their privileges to an administrative role. This escalation provides full control over the CFEngine hub, which can then be used to compromise the entire managed infrastructure. The vulnerability is addressed in versions 3.21.8, 3.24.3, and 3.27.0.
Affected products
- Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, 3.27.0
Timeline
- 2026-02-09: patched: Vendor blog post announcing fixes for multiple versions.
- 2026-05-14: disclosed: CVE published to NVD.