Northern.tech CFEngine Enterprise Access Control Vulnerability

Vulnerability

A broken access control vulnerability has been identified in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. This vulnerability allows an attacker with a low-privilege user account to access more information than permitted, and in severe cases, escalate privileges to an admin level.

Impact

Exploitation of this vulnerability could enable a low-privilege user to bypass access controls, escalate privileges, and gain control over the hub and the entire infrastructure managed by it.

Remediation

Users are advised to upgrade to CFEngine Enterprise versions 3.27.0, 3.24.3, or 3.21.8. Instructions for upgrading CFEngine can be found in the CFEngine documentation.

Added: May 14, 2026, 3:37 PM
Updated: May 14, 2026, 3:37 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
4.9
remediation
7.7
relevance
8.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.