Known Vulnerabilities for Puppet Enterprise by Perforce
Listed below are 3 of the newest known vulnerabilities associated with "Puppet Enterprise" by "Perforce".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-85979 json | Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd ... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-8804 json | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive fl... | Not Provided | 2026-07-03 | 2026-07-06 |
| CVE-2025-5459 json | A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands... | Not Provided | 2025-06-26 | 2026-09-04 |