Command Injection Vulnerability in Puppet Enterprise by Puppet
CVE-2026-85979
8.6HIGH
Key Information:
- Vendor
Perforce Software
- Status
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-85979?
Puppet Enterprise contains a command injection vulnerability through the improper handling of the java_keystore_passwd parameter. An authenticated user with administrative privileges can exploit this flaw by injecting malicious shell commands via specially crafted parameter values. The lack of proper sanitization allows these commands to be executed in a shell context with root privileges, potentially leading to complete system compromise.
Affected Version(s)
Puppet Enterprise Linux 2023.8.4 <= 2023.8.10
Puppet Enterprise Linux 2025.4.0 <= 2025.11.2
Puppet Enterprise Linux 2023.8.11
