Bug 2496777 (CVE-2026-8804) - CVE-2026-8804 resource_api: Puppet Core: Puppet Enterprise: Puppet resource_api: Cleartext storage of sensitive information due to improper flag preservation
Summary: CVE-2026-8804 resource_api: Puppet Core: Puppet Enterprise: Puppet resource_a...
Keywords:
Status: NEW
Alias: CVE-2026-8804
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 08:01 UTC by OSIDB Bzimport
Modified: 2026-07-31 00:12 UTC (History)
20 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-03 08:01:33 UTC
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.


Note You need to log in before you can comment on or make changes to this bug.