ZeroHour

CVE-2026-85979

large

Authenticated Command Injection in Puppet Enterprise Yields Root RCE

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

Puppet Enterprise contains an OS command injection flaw (CWE-78, with improper input validation and privilege issues) in its handling of the java_keystore_passwd parameter, where crafted values reach a shell execution context without sufficient sanitization. The flaw is triggered by an authenticated user who holds Puppet administrative privileges and supplies a specially crafted value for this parameter, causing arbitrary shell commands to run on the host. Because the injected commands execute with root privileges, an attacker who can inject them gains full compromise of the affected system, consistent with the high (8.6) CVSS 4.0 score driven by network attack vector and high system-level impacts. Organizations running affected versions of Puppet Enterprise are exposed, though exploitation requires valid high-privilege Puppet credentials rather than anonymous access. As of this analysis there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation is known.

What to do: Upgrade Puppet Enterprise to the fixed release identified in the vendor advisory (exact fixed version not specified in this data). In the meantime, restrict Puppet administrative console access to trusted personnel via least privilege and MFA, and review authentication and process/audit logs on Puppet servers for unexpected shell or child-process activity involving java_keystore_passwd handling. Since exploitation requires admin-level credentials, prioritize rotating and hardening Puppet admin accounts if compromise is suspected.

Affected
Puppet (Perforce) Puppet EnterpriseAffected versions not enumerated in the source data; users should check the vendor advisory ([email protected]) for the exact affected and fixed ranges
Estimated exposure
largeon the order of tens of thousands of Puppet Enterprise deployments (10k–100k primary servers) — Puppet Enterprise is a long-established enterprise configuration-management product with a large installed base typically deployed as one or a few primary servers per organization; because the data provides no scan counts or install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.

Weakness
CWE-20, CWE-78, CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.