Command Injection Vulnerability in Puppet Enterprise by Puppet
CVE-2026-85979

8.6HIGH

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-85979?

Puppet Enterprise contains a command injection vulnerability through the improper handling of the java_keystore_passwd parameter. An authenticated user with administrative privileges can exploit this flaw by injecting malicious shell commands via specially crafted parameter values. The lack of proper sanitization allows these commands to be executed in a shell context with root privileges, potentially leading to complete system compromise.

Affected Version(s)

Puppet Enterprise Linux 2023.8.4 <= 2023.8.10

Puppet Enterprise Linux 2025.4.0 <= 2025.11.2

Puppet Enterprise Linux 2023.8.11

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.