What is CVE-2026-66379?
CVE-2026-66379: An authenticated user may view private Puppet module metadata without repository read access. This could expose sensitive module information to unauthorized users. Applying the security update and reviewing access controls is recommended.
Azərbaycanca: CVE-2026-66379: Autentifikasiya olunmuş istifadəçi repository read icazəsi olmadan özəl Puppet modullarının metadatasını görə bilər. Bu boşluq istifadəçiyə aid olmayan həssas modul məlumatlarının ifşasına yol aça bilər. Təhlükəsizlik yeniləməsinin tətbiqi və giriş nəzarətlərinin nəzərdən keçirilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of users can exploit CVE-2026-66379?
This vulnerability can be exploited by authenticated users who do not have repository read access.
What data can be exposed through CVE-2026-66379?
This vulnerability could expose metadata of private Puppet modules that do not belong to the user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.