AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66379

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated users can access private Puppet module metadata without having the necessary repository read permissions, potentially exposing sensitive information. This vulnerability could lead to unauthorized disclosure of proprietary data, making it critical for organizations using Puppet to prioritize remediation. Users managing Puppet environments should assess their access controls to mitigate this risk.

CVE
CVE-2026-66379
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

An authenticated user may view private Puppet module metadata without repository read access.