CVE-2026-33553
MEDIUMCFEngine Enterprise 3.24.3-3.24.4 and 3.27.0-3.27.1 - Cross-Site Scripting
Title source: llmDescription
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
References (2)
Core 2
Scores
CVSS v3
6.1
EPSS
0.0017
EPSS Percentile
6.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Published
Jun 02, 2026
Tracked Since
Jun 03, 2026