CVE-2026-85979
Puppet vulnerability analysis and mitigation

Overview

CVE-2026-85979 is a command injection vulnerability in Puppet Enterprise affecting the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands via a specially crafted parameter value that is passed to a shell execution context without sufficient sanitization, resulting in command execution with root privileges. Affected versions include Puppet Enterprise 2023.8.0 through 2023.8.10 and 2025.0.0 through 2025.11.2. It carries a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Perforce Advisory).

Technical details

The root cause is improper neutralization of special elements used in an OS command (CWE-78) combined with improper input validation (CWE-20) and improper privilege management (CWE-269). The java_keystore_passwd parameter, supplied by an authenticated administrative user, is passed directly into a shell execution context without adequate sanitization, allowing shell metacharacters or command delimiters to break out of the intended command and inject arbitrary OS commands. Because the Puppet Enterprise service runs with root privileges, the injected commands inherit those elevated permissions. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Perforce Advisory).

Impact

Successful exploitation grants an attacker full root-level control of the affected Puppet Enterprise server, resulting in complete compromise of confidentiality, integrity, and availability of the vulnerable system. Because Puppet Enterprise typically manages configuration across a large fleet of nodes, a compromised Puppet master could be leveraged to push malicious configurations or code to all managed nodes, enabling broad lateral movement across the infrastructure. Sensitive data stored on or accessible by the Puppet Enterprise server — including certificates, secrets, and node configurations — would be fully exposed (GitHub Advisory, Perforce Advisory).

Exploitability

As of the disclosure date (September 11, 2026), there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been published (GitHub Advisory). Exploitation requires authentication with Puppet administrative privileges, which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.974% (61st percentile), indicating a moderate near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported. NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable (Feedly).

Exploitation steps

  1. Gain Administrative Access: Obtain valid credentials for a Puppet Enterprise account with administrative privileges, either through credential theft, phishing, or insider access.
  2. Identify the Vulnerable Parameter: Locate the interface or API endpoint in Puppet Enterprise that accepts the java_keystore_passwd parameter (e.g., within the PE console or API for keystore configuration).
  3. Craft Malicious Payload: Construct a value for java_keystore_passwd that includes shell metacharacters or command delimiters to break out of the intended command context, for example: validpassword; id; whoami or validpassword$(malicious_command).
  4. Submit the Payload: Submit the crafted parameter value through the Puppet Enterprise administrative console or via an authenticated API call to the relevant configuration endpoint.
  5. Achieve Root Code Execution: The unsanitized value is passed to a shell execution context running as root, causing the injected commands to execute with full root privileges on the Puppet Enterprise server.
  6. Establish Persistence / Lateral Movement: Use root access to install backdoors, exfiltrate credentials, or push malicious Puppet manifests to managed nodes to propagate compromise across the infrastructure (GitHub Advisory, Perforce Advisory).

Indicators of compromise

  • Logs: Puppet Enterprise access logs showing administrative API calls or console actions involving the java_keystore_passwd parameter with unusual or encoded values; system auth logs (/var/log/auth.log or /var/log/secure) showing unexpected root-level command execution originating from the Puppet service account.
  • Process: Unexpected child processes spawned by the Puppet Enterprise Java process (e.g., /bin/sh, /bin/bash, curl, wget, nc, python) visible in process trees via ps or EDR telemetry.
  • File System: New or modified files in Puppet Enterprise directories, unexpected cron jobs, SSH authorized_keys modifications, or web shells placed on the server by the Puppet service account.
  • Network: Unusual outbound network connections from the Puppet Enterprise server to external IPs, particularly on non-standard ports, which may indicate reverse shell or data exfiltration activity.
  • Puppet Manifests: Unexpected or unauthorized changes to Puppet manifests, modules, or Hiera data that could indicate an attacker attempting to propagate malicious configurations to managed nodes.

Mitigation and workarounds

Perforce has released patched versions: Puppet Enterprise 2023.8.11 (for the 2023.8.x branch) and Puppet Enterprise 2025.11.3 (for the 2025.x branch). Organizations should upgrade to these versions immediately. As interim mitigations, restrict Puppet administrative privileges to the minimum number of trusted users, monitor Puppet Enterprise systems for unusual shell command execution, review access logs for suspicious administrative activity, and consider network segmentation to limit exposure of the Puppet Enterprise infrastructure (GitHub Advisory, Perforce Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

puppetserver

Fixed

sid

puppetserver

Fixed

trixie

puppetserver

Fixed

Ubuntu

Unknown

devel

puppetserver

Unknown

noble

puppetserver

Unknown

noble (esm-apps)

puppetserver

Unknown

resolute

puppetserver

Unknown

resolute (esm-apps)

puppetserver

Unknown

SourceThis report was generated using AI

Related Puppet vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85979HIGH8.6
  • Puppet logoPuppet
  • puppetserver
NoNoSep 11, 2026
CVE-2023-5255HIGH7.5
  • Puppet logoPuppet
  • cpe:2.3:a:puppet:puppet
NoNoOct 03, 2023
CVE-2023-1894MEDIUM5.3
  • Puppet logoPuppet
  • puppet
NoYesMay 04, 2023
CVE-2021-27026MEDIUM4.4
  • Puppet logoPuppet
  • puppet
NoYesNov 18, 2021
CVE-2026-66379MEDIUM4.3
  • Puppet logoPuppet
  • artifactory
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management