Executive brief
Puppet Enterprise is a configuration management platform used to automate infrastructure deployment and management across servers. A flaw allows authenticated administrators to inject arbitrary shell commands through a specially crafted parameter, leading to full system compromise with root-level privileges. This could enable attackers with admin credentials to take over managed systems and potentially the entire infrastructure.
Technical details
The vulnerability is a command injection flaw in Puppet Enterprise where user-supplied input to an administrative parameter is passed to a shell execution context without adequate sanitization. The attack requires valid Puppet administrative privileges and network access to the affected system. A successful exploit allows execution of arbitrary shell commands with root privileges, resulting in complete system compromise. Patches are available in Puppet Enterprise 2023.8.11 and 2025.11.3.
Affected products
- Puppet Enterprise 2023.8.0 through 2023.8.10, 2025.0.0 through 2025.11.2
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Puppet Enterprise 2023.8.11 and 2025.11.3