Impact
An authenticated Puppet administrator can inject arbitrary shell commands by providing a specially crafted value for an internal parameter. That value is passed directly to a shell execution context without sufficient sanitization, enabling execution of arbitrary commands. Because the commands run with root privileges, exploitation can lead to full compromise of the affected system, affecting confidentiality, integrity, and availability.
Affected Systems
Perforce Software’s Puppet Enterprise platform is impacted. Vulnerable versions include Puppet Enterprise 2023.8.0 through 2023.8.10 and Puppet Enterprise 2025.0.0 through 2025.11.2. Any deployment running these versions should verify the installed version and upgrade promptly.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV. The attack vector is local: the attacker must be authenticated with Puppet administrative privileges, but once achieved the ability to execute arbitrary commands as root presents a full compromise potential.
OpenCVE Enrichment