Junglewise Threat Intelligence

CVE-2026-33553: Northern.tech CFEngine Enterprise XSS in Mission Portal

CVE-2026-33553 · Severity: info · CVSS 0 · Published 2026-06-02

Technologies: Northern.tech CFEngine Enterprise. Vendors: Northern.tech.

Executive brief

A security vulnerability exists in CFEngine Enterprise, a platform used for automated device management and infrastructure configuration. An attacker with low-level access could trick an administrator into clicking a malicious link, allowing the attacker to run unauthorized code in the administrator's browser. If successful, this could lead to a full takeover of the management hub and all connected infrastructure.

Technical details

A cross-site scripting (XSS) vulnerability exists in the CFEngine Enterprise Mission Portal due to an incorrect Content-Type HTTP header returned by certain API endpoints. This misconfiguration allows browsers to execute JavaScript contained within API responses that may include user-controlled data. An authenticated attacker with low privileges can exploit this by injecting malicious scripts into specific fields and then enticing an administrator to click a crafted API link. Successful exploitation allows the attacker to execute code in the context of the administrator's session, leading to privilege escalation and potential full control over the CFEngine hub and managed nodes. The issue is fixed in versions 3.24.4 and 3.27.1.

Affected products

  • Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4, 3.27.0 before 3.27.1

Timeline

  • 2026-05-08: patched: Versions 3.24.4 and 3.27.1 released
  • 2026-06-01: advisory: Vendor blog post published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats