VendorsNorthern.techcfengineall versions
Vulnerabilities

Northern.tech Cfengine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-45684
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
Published 2023-11-14 · Modified
7.5EPSS 0.006
CVE-2026-24712
Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
Published 2026-05-14 · Analyzed
7.3EPSS 0.009
CVE-2023-26560
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
Published 2023-04-25 · Modified
6.5EPSS 0.005
CVE-2021-36756
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
Published 2021-10-27 · Modified
6.5EPSS 0.004
CVE-2019-19394
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
Published 2020-04-16 · Modified
6.1EPSS 0.006
CVE-2026-24710
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
Published 2026-05-14 · Analyzed
6.1EPSS 0.002
CVE-2021-44216
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
Published 2022-03-07 · Modified
5.5EPSS 0.004
CVE-2021-44215
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
Published 2022-03-07 · Modified
5.5EPSS 0.004
CVE-2021-38379
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
Published 2021-10-27 · Modified
5.5EPSS 0.002
CVE-2026-24711
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
Published 2026-05-14 · Analyzed
5.3EPSS 0.002