Junglewise Threat Intelligence

CVE-2026-49009: Northern.tech Mender Server directory traversal in artifact creation endpoint

CVE-2026-49009 · Severity: info · CVSS 8.8 · Published 2026-05-27

Vendors: Northern.tech.

Executive brief

Northern.tech Mender Server, a platform used for managing over-the-air (OTA) software updates for IoT devices, contains a security flaw in its artifact creation process. An attacker with a valid user account could exploit this to access restricted files on the server and inject malicious code into software updates. If successful, this could lead to the distribution of compromised software to connected devices, though devices using cryptographic signature verification are protected from installing these malicious updates.

Technical details

A directory traversal vulnerability exists in the Mender Server API and UI endpoint used for creating artifacts. Due to improper input sanitization of request parameters, an authenticated attacker can use path traversal sequences (e.g., '../') to access and modify files outside of the intended directory within the server container. This allows an attacker to inject arbitrary malicious code into artifacts during the creation process. The impact is particularly high in multi-tenant environments where an attacker can easily obtain low-privileged credentials. The vulnerability is mitigated if the Mender Client is configured to verify cryptographically signed artifacts. Fixed versions include 4.1.1 and 4.0.2.

Affected products

  • Northern.tech Mender Server 4.1.0, 4.0.1 and below

Timeline

  • 2026-05-27: disclosed: Disclosed via Northern.tech blog and HackerOne program
  • 2026-05-27: patched: Fixed in versions 4.1.1 and 4.0.2
  • 2026-05-27: advisory

References