Puppet (Perforce)
First CVE: Feb 8, 2017Active for: 9 years
91
CVEs Published
More CVEs Published than 69% of tracked CNAs
9.1
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Puppet (Perforce) as a CNA, 60.4% affect products that Puppet (Perforce) develops as a vendor.
60.4%
39.6%
Self-reported: 55Third-party: 36
Of all the CVEs published that affect products developed by Puppet (Perforce), 42.6% are self-published by Puppet (Perforce) as a CNA.
42.6%
57.4%
Self-published: 55Published by other CNAs: 74
Trends Over Time
The number and severity of CVEs published by Puppet (Perforce) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2017
9 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
Top CVEs
All CVEs published by Puppet (Perforce) as a CNA, regardless of affected vendor or product.
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14254HIGH A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login | Jul 16, 2026 | 8.3 | 34 | NO | NO |
CVE-2026-8654HIGH Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host. | May 15, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-6043HIGH P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user | Apr 24, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-8804MEDIUM Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing | Jul 3, 2026 | 6.7 | 31 | NO | NO |
CVE-2026-6902HIGH A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks. | May 18, 2026 | 7.7 | 31 | NO | NO |
CVE-2023-45849CRITICAL An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
| Nov 8, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-3275CRITICAL Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsaniti | Oct 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-27023CRITICAL A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018 | Nov 18, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-7943HIGH Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server | Mar 11, 2020 | 7.5 | 31 | NO | YES |
CVE-2019-10694CRITICAL The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, | Dec 12, 2019 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA91 CVEs
36%
42%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (14.3%)
Network76 (83.5%)
Unknown0 (0.0%)
Physical1 (1.1%)
Adjacent Network1 (1.1%)
Attack Complexity
Low85 (93.4%)
High6 (6.6%)
Unknown0 (0.0%)
User Interaction
None78 (85.7%)
Unknown0 (0.0%)
Required9 (9.9%)
Privileges Required
Low38 (41.8%)
High9 (9.9%)
None44 (48.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (91 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 80th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Puppet (Perforce) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Puppet (Perforce) as a CNA — matched by CVE ID, not by organization name.