CVE-2026-85979
largeAuthenticated Command Injection in Puppet Enterprise Yields Root RCE
Puppet Enterprise contains an OS command injection flaw (CWE-78, with improper input validation and privilege issues) in its handling of the java_keystore_passwd parameter, where crafted values reach a shell execution context without sufficient sanitization. The flaw is triggered by an authenticated user who holds Puppet administrative privileges and supplies a specially crafted value for this parameter, causing arbitrary shell commands to run on the host. Because the injected commands execute with root privileges, an attacker who can inject them gains full compromise of the affected system, consistent with the high (8.6) CVSS 4.0 score driven by network attack vector and high system-level impacts. Organizations running affected versions of Puppet Enterprise are exposed, though exploitation requires valid high-privilege Puppet credentials rather than anonymous access. As of this analysis there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation is known.
What to do: Upgrade Puppet Enterprise to the fixed release identified in the vendor advisory (exact fixed version not specified in this data). In the meantime, restrict Puppet administrative console access to trusted personnel via least privilege and MFA, and review authentication and process/audit logs on Puppet servers for unexpected shell or child-process activity involving java_keystore_passwd handling. Since exploitation requires admin-level credentials, prioritize rotating and hardening Puppet admin accounts if compromise is suspected.
| Puppet (Perforce) Puppet Enterprise | Affected versions not enumerated in the source data; users should check the vendor advisory ([email protected]) for the exact affected and fixed ranges |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.
- Weakness
- CWE-20, CWE-78, CWE-269
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.