yocto ▾
›
master ▾
›
vulnerability
›
CVE-2026-24711
Component Overview
Vulnerability Overview
Name
CVE-2026-24711
Source
NVD (
link
)
Debian (
link
)
Description
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CWEs
CWE-284
Published Date
May 14, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/
Mitigation
https://northern.tech
Product
Analysis
#
Affected Component
Analysis
cfengine
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
cfengine
yocto
kirkstone
3.15.0
Exploitable
cfengine
yocto
scarthgap
3.21.0
Exploitable