puppet_enterprise vulnerabilities
CVEs whose affected-version data names the puppet_enterprise package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-85979High· 8.6Affected versions of Puppet Enterprise contain a command injection vulnerability
Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …
▾ TwilightPerforce Software · Puppet EnterpriseEPSS 0.97%via NVD
CVE-2025-5459High· 8.8A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has…
▾ Twilightpuppet · puppet_enterpriseEPSS 0.49%via NVD