๐Ÿ” CVE Alert

CVE-2026-85979

UNKNOWN 0.0

Command Injection in Puppet Enterprise

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.

CWE CWE-78 CWE-20 CWE-269
Vendor perforce software
Product puppet enterprise
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for perforce software puppet enterprise

Be the first to know when new unknown vulnerabilities affecting perforce software puppet enterprise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Perforce Software / Puppet Enterprise
2023.8.4 โ‰ค 2023.8.10 2025.4.0 โ‰ค 2025.11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
portal.perforce.com: https://portal.perforce.com/s/cve/a91Qi000003CybNIAS/command-injection-in-puppet-enterprise