← Vulnerability feed

Vulnerability record · CVE-2016-5714 · published 18 October 2017

CVE-2016-5714: Puppet enterprise improper access control vulnerability

Puppet · Puppet Enterprise

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."

7.2 CVSS 3.1 High EPSS 2.2% · top 17.8% CWE-284 · Improper access control
7.2CVSS 3.1 base score, v2 6.5
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-5714 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5309Puppet enterprise vulnerabilityVersions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.EPSS 0.50%9.8CVE-2023-2530Puppet enterprise vulnerabilityA privilege escalation allowing remote code execution was discovered in the orchestration service.EPSS 1.1%9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2019-10694Puppet enterprise hard-coded credentials vulnerabilityThe express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…EPSS 1.1%9.8CVE-2018-11749Puppet enterprise cleartext transmission vulnerabilityWhen users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…EPSS 0.76%9.8CVE-2018-6512Puppet pe-razor-server code injection vulnerabilityThe previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …EPSS 1.9%9.8CVE-2016-5713Puppet agent code injection vulnerabilityVersions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …EPSS 2.0%9.8CVE-2016-2788Puppet marionette collective improper access control vulnerabilityMCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2016-5714), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.