Junglewise Threat Intelligence

CVE-2026-85979: Puppet Enterprise command injection in administrative parameter

CVE-2026-85979 · Severity: info · Published 2026-09-11

Executive brief

Puppet Enterprise is a configuration management platform used to automate infrastructure deployment and management across servers. A flaw allows authenticated administrators to inject arbitrary shell commands through a specially crafted parameter, leading to full system compromise with root-level privileges. This could enable attackers with admin credentials to take over managed systems and potentially the entire infrastructure.

Technical details

The vulnerability is a command injection flaw in Puppet Enterprise where user-supplied input to an administrative parameter is passed to a shell execution context without adequate sanitization. The attack requires valid Puppet administrative privileges and network access to the affected system. A successful exploit allows execution of arbitrary shell commands with root privileges, resulting in complete system compromise. Patches are available in Puppet Enterprise 2023.8.11 and 2025.11.3.

Affected products

  • Puppet Enterprise 2023.8.0 through 2023.8.10, 2025.0.0 through 2025.11.2

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Puppet Enterprise 2023.8.11 and 2025.11.3

References