HIGH8.1
PYSEC-2026-1899
Salt has minion event bus authorization bypass vulnerability
Quick fix
PYSEC-2026-1899 — salt: upgrade to the fixed version with the command below.
pip install --upgrade 'salt>=3006.12'Details
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-22236[ADVISORY]
- https://docs.saltproject.io/en/3006/topics/releases/3006.12.html[WEB]
- https://docs.saltproject.io/en/3007/topics/releases/3007.4.html[WEB]
- https://github.com/saltstack/salt[PACKAGE]
- https://pypi.org/project/salt[PACKAGE]
- https://github.com/advisories/GHSA-jh7c-xh74-h76f[ADVISORY]