
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62349 is an authentication protocol version downgrade vulnerability in SaltStack Salt, titled "Salt Master Authentication Protocol Downgrade May Enable Minion Impersonation." It affects Salt versions 3006.12 through 3006.17 (exclusive) and 3007.4 through 3007.9 (exclusive), and was published on January 30, 2026. The flaw allows a malicious minion to bypass newer authentication and security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues. It carries a CVSS v3.1 base score of 6.2 (Medium) and a CVSS v4.0 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-287 (Improper Authentication) and CWE-305 (Authentication Bypass by Primary Weakness). The vulnerability exists because the Salt Master does not enforce the use of newer authentication protocol versions, allowing a minion with high privileges to craft and submit requests using an older payload format that bypasses security controls introduced in recent releases. This downgrade attack vector is network-accessible and requires no user interaction, though it does require the attacker to already possess high-level minion credentials and specific deployment conditions (Attack Requirements: Present). The issue was tracked in the SaltStack repository and referenced in commit 3d5708a (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a malicious minion to impersonate legitimate minions on the Salt infrastructure, resulting in high confidentiality and integrity impact — an attacker could gain unauthorized access to sensitive configuration data and secrets managed by the Salt Master, as well as modify system configurations or issue unauthorized commands to managed nodes. Availability impact is rated low. The compromise of Salt Master trust relationships could enable lateral movement across all managed minions in the infrastructure, potentially affecting the entire configuration management estate (GitHub Advisory, Red Hat Bugzilla).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.018–0.02%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already hold high-privilege minion credentials, which limits the attack surface but does not eliminate risk in environments with compromised or rogue minions.
/var/log/salt/master) showing authentication events from known minion IDs originating from unexpected IP addresses; repeated authentication attempts using mismatched payload formats./etc/salt/pki/master/minions/ that do not correspond to known managed hosts.Salt Project has released patched versions 3006.17 and 3007.9 which address this vulnerability; users should upgrade immediately (GitHub Advisory). As interim workarounds, administrators should implement network segmentation to restrict Salt Master ports (4505/4506) to only trusted minion networks, audit and revoke any suspicious or unauthorized minion keys, and monitor Salt authentication logs for anomalous minion behavior or requests using unexpected payload formats. Restricting minion connectivity to authorized hosts via firewall rules reduces the attack surface while patches are deployed.
Red Hat tracked the vulnerability via their security response process (Bugzilla Bug 2435539) and assigned it medium severity, with the issue reported by OSIDB Bzimport on January 30, 2026 (Red Hat Bugzilla). SUSE issued advisories for their Linux Manager and Salt bundle products referencing this CVE. Security aggregators including Tenable (Nessus plugins 279354, 279364, 279360, 279372, 279377, 297654) and Qualys added detection coverage shortly after disclosure. Coverage was also noted in German Linux security outlet pro-linux.de and the Secret CISO newsletter, indicating moderate community awareness without significant alarm given the lack of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."