HIGH
Perforce Software
CVE published 2026-09-11
CVE-2026-85979
A command injection vulnerability exists in Puppet Enterprise due to insufficient sanitization of the java_keystore_passwd parameter. An authenticated user with administrative privileges can inject arbitrary shell commands, potentially leading to full system compromise. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. System administrators and security teams should assess thei [truncated]