CVE-2016-2787: Puppet Enterprise

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

Affected products

  • Puppet Puppet Enterprise: version 2015.3.2 only
  • Puppetlabs Puppet Enterprise: version 2015.3 only

Published 2017-02-13. Last modified 2026-06-17.