Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
{ "binaries": [ { "binary_version": "3.6.2-4ubuntu1", "binary_name": "cfengine3" }, { "binary_version": "3.6.2-4ubuntu1", "binary_name": "libpromises3" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24712.json"
{ "binaries": [ { "binary_version": "3.10.2-4build1", "binary_name": "cfengine3" }, { "binary_version": "3.10.2-4build1", "binary_name": "libpromises3" } ] }
{ "binaries": [ { "binary_version": "3.12.1-2", "binary_name": "cfengine3" }, { "binary_version": "3.12.1-2", "binary_name": "libpromises3" } ] }
{ "binaries": [ { "binary_version": "3.21.0-3", "binary_name": "cfengine3" }, { "binary_version": "3.21.0-3", "binary_name": "libpromises3" } ] }
{ "binaries": [ { "binary_version": "3.24.2-1build1", "binary_name": "cfengine3" }, { "binary_version": "3.24.2-1build1", "binary_name": "libpromises3" } ] }