Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85979— Command Injection in Puppet Enterprise

Quick assessment

Affected
Perforce Software Puppet Enterprise
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

受影响的 Puppet Enterprise 版本中,在 参数的处理过程中存在一个命令注入漏洞。拥有 Puppet 管理员权限的认证用户通过为该参数提供特制值,可以向一个缺乏充分净化的 shell 执行上下文中注入任意 shell 命令。由于生成的命令以 root 权限执行,成功利用该漏洞可能导致受影响系统的完全失陷。

CVSS 8.6 · High

Possible ATT&CK Techniques 1 AI

T1059.004 · Unix Shell
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85979

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Command Injection in Puppet Enterprise
Source: CVE Program / CVE List V5
Vulnerability Description
Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Perforce Software Puppet Enterprise 2023.8.4 ~ 2023.8.10 -

II. Public POCs for CVE-2026-85979

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85979

登录查看更多情报信息。

Vendor Pages for CVE-2026-85979 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85979

No comments yet


Leave a comment