
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85979 is a command injection vulnerability in Puppet Enterprise affecting the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands via a specially crafted parameter value that is passed to a shell execution context without sufficient sanitization, resulting in command execution with root privileges. Affected versions include Puppet Enterprise 2023.8.0 through 2023.8.10 and 2025.0.0 through 2025.11.2. It carries a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Perforce Advisory).
The root cause is improper neutralization of special elements used in an OS command (CWE-78) combined with improper input validation (CWE-20) and improper privilege management (CWE-269). The java_keystore_passwd parameter, supplied by an authenticated administrative user, is passed directly into a shell execution context without adequate sanitization, allowing shell metacharacters or command delimiters to break out of the intended command and inject arbitrary OS commands. Because the Puppet Enterprise service runs with root privileges, the injected commands inherit those elevated permissions. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Perforce Advisory).
Successful exploitation grants an attacker full root-level control of the affected Puppet Enterprise server, resulting in complete compromise of confidentiality, integrity, and availability of the vulnerable system. Because Puppet Enterprise typically manages configuration across a large fleet of nodes, a compromised Puppet master could be leveraged to push malicious configurations or code to all managed nodes, enabling broad lateral movement across the infrastructure. Sensitive data stored on or accessible by the Puppet Enterprise server — including certificates, secrets, and node configurations — would be fully exposed (GitHub Advisory, Perforce Advisory).
As of the disclosure date (September 11, 2026), there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been published (GitHub Advisory). Exploitation requires authentication with Puppet administrative privileges, which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.974% (61st percentile), indicating a moderate near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported. NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable (Feedly).
java_keystore_passwd parameter (e.g., within the PE console or API for keystore configuration).java_keystore_passwd that includes shell metacharacters or command delimiters to break out of the intended command context, for example: validpassword; id; whoami or validpassword$(malicious_command).java_keystore_passwd parameter with unusual or encoded values; system auth logs (/var/log/auth.log or /var/log/secure) showing unexpected root-level command execution originating from the Puppet service account./bin/sh, /bin/bash, curl, wget, nc, python) visible in process trees via ps or EDR telemetry.Perforce has released patched versions: Puppet Enterprise 2023.8.11 (for the 2023.8.x branch) and Puppet Enterprise 2025.11.3 (for the 2025.x branch). Organizations should upgrade to these versions immediately. As interim mitigations, restrict Puppet administrative privileges to the minimum number of trusted users, monitor Puppet Enterprise systems for unusual shell command execution, review access logs for suspicious administrative activity, and consider network segmentation to limit exposure of the Puppet Enterprise infrastructure (GitHub Advisory, Perforce Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."