← Vulnerability feed

Vulnerability record · CVE-2016-2785 · published 10 June 2016

CVE-2016-2785: Puppet improper access control vulnerability

Puppet · Puppet

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

9.8 CVSS 3.1 Critical EPSS 2.9% · top 13.6% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 7.5
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2785 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2016-5713Puppet agent code injection vulnerabilityVersions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …EPSS 2.0%9.8CVE-2016-2786Puppet agent improper input validation vulnerabilityThe pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…EPSS 1.6%9.0CVE-2013-1640Puppet vulnerabilityThe (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pup…EPSS 4.9%8.8CVE-2021-27021Puppet sql injection vulnerabilityA flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.EPSS 1.3%8.8CVE-2018-6513Puppet untrusted search path vulnerabilityPuppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Age…EPSS 1.1%8.2CVE-2017-2295Puppet deserialization of untrusted data vulnerabilityVersions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. …EPSS 2.4%7.8CVE-2018-6514Puppet untrusted search path vulnerabilityIn Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a D…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2016-2785), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.