Northern.Tech · Cfengine · CVE-2026-24711
**Name of the Vulnerable Software and Affected Versions**
CFEngine Enterprise versions prior to 3.21.8
CFEngine Enterprise versions prior to 3.24.3
CFEngine Enterprise versions prior to 3.27.0
**Description**
Incorrect access control allows cross-site scripting (XSS), a technique where malicious scripts are injected into otherwise trusted websites.
**Recommendations**
Update to version 3.21.8.
Update to version 3.24.3.
Update to version 3.27.0.