Cleartext Storage of Sensitive Information for Puppet Resource API
Published Jul 3, 2026
6.7
MEDIUMCVSS 4.0
EPSS 0.11%
Description
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.
Affected products
-
- Version 8.0.0StatusaffectedConstraints<=8.10.0
- Version 8.11.0StatusaffectedConstraints<=8.19.0
- Version 8.20.0StatusunaffectedConstraints-
- Version
-
- Version 2023.8.0StatusaffectedConstraints<=2023.8.9
- Version 2025.0.0StatusaffectedConstraints<=2025.10.0
- Version 2023.8.10StatusunaffectedConstraints-
- Version 2025.11.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Perforce | Puppet Core | unaffected |
| |||||||||||||||
| Perforce | Puppet Enterprise | unaffected |
|
No data.
No data.
Red Hat OpenStack Platform 17.1
rubygem-puppet-resource_api
Fix deferred
Red Hat Satellite 6
puppet-agent
Fix deferred
Red Hat Satellite 6
satellite-capsule:el8/puppet-agent
Fix deferred
Red Hat Satellite 6
satellite:el8/puppet-agent
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 17.1 | rubygem-puppet-resource_api | Fix deferred | n/a |
| Red Hat Satellite 6 | puppet-agent | Fix deferred | n/a |
| Red Hat Satellite 6 | satellite-capsule:el8/puppet-agent | Fix deferred | n/a |
| Red Hat Satellite 6 | satellite:el8/puppet-agent | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to Puppet Core 8.20.0, PE 2023.8.10, or PE 2025.11.0
Red Hat statement
Red Hat OpenStack Platform 17.1 ships rubygem-puppet-resource_api version 1.8.13, which is within the affected range (1.5.0-1.9.1). Red Hat Satellite ships puppet-agent which bundles the resource_api gem; investigation is ongoing to determine if those versions are in the affected range. The sensitive flag on resource_api parameters is not properly preserved, causing values such as passwords to be stored in cleartext in the Puppet agent's local transaction state cache.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-8804 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496777 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41516 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8804
- https://portal.perforce.com/s/cve/a91Qi000003511lIAA/cve20268804-cleartext-storage-of-sensitive-information-for-puppet-resource-api
- https://www.cve.org/CVERecord?id=CVE-2026-8804
Change history (0)
No recorded changes yet.