CVE-2026-66379: Authenticated users may view private Puppet module metadata
Published Aug 12, 2026
·Updated
An authenticated user may view private Puppet module metadata without repository read access.
Affected Software
1 affected component
Puppet
Event History
Aug 12, 2026
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66379?
The severity of CVE-2026-66379 is rated as medium with a score of 4.3.
2
Who is affected by CVE-2026-66379?
Authenticated users with access to Puppet may be affected by CVE-2026-66379 if they can view private module metadata.
3
What data can be exposed due to CVE-2026-66379?
CVE-2026-66379 allows authenticated users to view private Puppet module metadata without the need for repository read access.
4
How do I fix CVE-2026-66379?
To address CVE-2026-66379, ensure that appropriate access controls are enforced for Puppet module metadata.
5
What software version is affected by CVE-2026-66379?
CVE-2026-66379 affects the Puppet software, specifically versions that allow inappropriate metadata access for authenticated users.