Executive brief
Northern.tech Mender Server, a platform used for managing over-the-air (OTA) software updates for IoT devices, contains a security flaw in its artifact creation process. An attacker with a valid user account could exploit this to access restricted files on the server and inject malicious code into software updates. If successful, this could lead to the distribution of compromised software to connected devices, though devices using cryptographic signature verification are protected from installing these malicious updates.
Technical details
A directory traversal vulnerability exists in the Mender Server API and UI endpoint used for creating artifacts. Due to improper input sanitization of request parameters, an authenticated attacker can use path traversal sequences (e.g., '../') to access and modify files outside of the intended directory within the server container. This allows an attacker to inject arbitrary malicious code into artifacts during the creation process. The impact is particularly high in multi-tenant environments where an attacker can easily obtain low-privileged credentials. The vulnerability is mitigated if the Mender Client is configured to verify cryptographically signed artifacts. Fixed versions include 4.1.1 and 4.0.2.
Affected products
- Northern.tech Mender Server 4.1.0, 4.0.1 and below
Timeline
- 2026-05-27: disclosed: Disclosed via Northern.tech blog and HackerOne program
- 2026-05-27: patched: Fixed in versions 4.1.1 and 4.0.2
- 2026-05-27: advisory