Undefined · Undefined · CVE-2026-33553
**Name of the Vulnerable Software and Affected Versions**
CFEngine Enterprise version 3.24.3
CFEngine Enterprise version 3.27.0
**Description**
Cross-site Scripting (XSS) is possible, which occurs when an application includes untrusted data in a web page without proper validation or escaping, allowing an attacker to execute malicious scripts in the victim's browser.
**Recommendations**
Update CFEngine Enterprise version 3.24.3 to 3.24.4.
Update CFEngine Enterprise version 3.27.0 to 3.27.1.