Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. | |
| Weaknesses | CWE-20 CWE-269 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-09-11T17:23:13.292Z
Reserved: 2026-09-04T18:45:39.755Z
Link: CVE-2026-85979
Updated: 2026-09-11T15:00:46.660Z
Status : Received
Published: 2026-09-11T15:17:06.807
Modified: 2026-09-11T16:17:47.750
Link: CVE-2026-85979
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:15:05Z