Known Vulnerabilities for products from Northern.tech

Listed below are 14 of the newest known vulnerabilities associated with the vendor "Northern.tech".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-49009 json Not Provided 2026-05-27 2026-05-28
CVE-2026-33553 json Not Provided 2026-06-02 2026-06-02
CVE-2026-33552 json Not Provided 2026-05-27 2026-05-28
CVE-2026-24712 json Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. Not Provided 2026-05-14 2026-05-19
CVE-2026-24711 json Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. Not Provided 2026-05-14 2026-05-19
CVE-2026-24710 json Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. Not Provided 2026-05-14 2026-05-19
CVE-2025-67903 json Not Provided 2026-05-27 2026-05-29
CVE-2023-45684 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2023-11-14 2023-11-20
CVE-2023-26560 json Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feat... 6.5 - MEDIUM 2023-04-26 2023-05-08
CVE-2022-32290 json The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged... 4.3 - MEDIUM 2022-07-06 2022-07-14
CVE-2022-29556 json The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub inte... 9.8 - CRITICAL 2022-04-28 2022-05-10
CVE-2022-29555 json The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket H... 8.8 - HIGH 2022-04-28 2022-05-10
CVE-2021-44216 json Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized... 5.5 - MEDIUM 2022-03-10 2022-03-15
CVE-2021-44215 json Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to ha... 5.5 - MEDIUM 2022-03-10 2022-03-15
CVE-2021-38379 json The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. 5.5 - MEDIUM 2021-10-27 2021-11-04
CVE-2021-36756 json CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. 6.5 - MEDIUM 2021-10-27 2021-11-04
CVE-2021-35342 json The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterp... 7.5 - HIGH 2021-08-27 2021-09-01
CVE-2019-19394 json Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixe... 6.1 - MEDIUM 2020-04-16 2020-04-22

Known software with vulnerabilities from Northern.tech

Type Vendor Product Version
ApplicationNorthern.techCfengine3.12.1