Northern.tech CFEngine Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Northern.tech CFEngine Enterprise and Community versions prior to 3.21.8, 3.24.3, and 3.27.0. This vulnerability arises from missing input sanitization in the CFEngine policy language, allowing injected shell commands to be executed inappropriately, particularly when custom policies process external data.

Impact

Exploitation of this vulnerability could enable an attacker to inject and execute arbitrary shell commands on the hub, especially through custom policies that manage users or similar resources.

Remediation

Users are advised to upgrade to CFEngine version 3.27.0, 3.24.3, 3.21.8, or later. Instructions for upgrading CFEngine are available in the CFEngine documentation.

Added: May 14, 2026, 3:37 PM
Updated: May 14, 2026, 3:37 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.9
remediation
7.7
relevance
8.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.