Command Injection in Puppet Enterprise
Summary
| CVE | CVE-2026-85979 |
|---|---|
| State | PUBLISHED |
| Assigner | Perforce |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 15:17:06 UTC |
| Updated | 2026-09-18 19:30:42 UTC |
| Description | Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. It affects Puppet Enterprise 2023.8.0 through 2023.8.10 and Puppet Enterprise 2025.0.0 through 2025.11.2. This has been resolved in Puppet Enterprise 2023.8.11 and Puppet Enterprise 2025.11.3. |
Risk And Classification
Primary CVSS: v4.0 8.6 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.009740000 probability, percentile 0.600400000 (date 2026-09-21)
Problem Types: CWE-20 | CWE-78 | CWE-269 | CWE-78 CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') | CWE-20 CWE-20 Improper input validation | CWE-269 CWE-269 Improper Privilege Management
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Perforce Software | Puppet Enterprise | affected 2023.8.0 2023.8.10 semver | Linux |
| CNA | Perforce Software | Puppet Enterprise | affected 2025.0.0 2025.11.2 semver | Linux |
| CNA | Perforce Software | Puppet Enterprise | unaffected 2023.8.11 semver | Linux |
| CNA | Perforce Software | Puppet Enterprise | unaffected 2025.11.3 semver | Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.perforce.com/s/cve/a91Qi000003CybNIAS/command-injection-in-puppet-enterprise | [email protected] | portal.perforce.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.