UBUNTU-CVE-2026-85979

Source
https://ubuntu.com/security/CVE-2026-85979
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85979.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-85979
Upstream
  • CVE-2026-85979
Published
2026-09-11T15:17:00Z
Modified
2026-09-24T02:00:37Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. It affects Puppet Enterprise 2023.8.0 through 2023.8.10 and Puppet Enterprise 2025.0.0 through 2025.11.2. This has been resolved inĀ Puppet Enterprise 2023.8.11 andĀ Puppet Enterprise 2025.11.3.

References

Affected packages

Ubuntu:24.04:LTS / puppetserver

Package

Name
puppetserver
Purl
pkg:deb/ubuntu/puppetserver?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.9.5-2
8.*
8.4.0-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "puppet-master",
            "binary_version":  "8.4.0-1"
        },
        {
            "binary_name":  "puppet-master-passenger",
            "binary_version":  "8.4.0-1"
        },
        {
            "binary_name":  "puppetserver",
            "binary_version":  "8.4.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85979.json"

Ubuntu:26.04:LTS / puppetserver

Package

Name
puppetserver
Purl
pkg:deb/ubuntu/puppetserver?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.7.0-3
8.7.0-6
8.7.0-6ubuntu1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "puppetserver",
            "binary_version":  "8.7.0-6ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85979.json"