CVE-2016-2788: Puppet Marionette Collective

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.

Affected products

  • Puppet Marionette Collective: version 2.7.0 only; version 2.8.0 only; version 2.8.1 only; version 2.8.2 only; version 2.8.3 only; version 2.8.4 only; …
  • Puppet Puppet Enterprise: from 3.8.0, before 3.8.6 (fixed in 3.8.6); from 2016.2.0, before 2016.2.1 (fixed in 2016.2.1)

Published 2017-02-13. Last modified 2026-06-17.