CVE-2025-22236
High
Salt has minion event bus authorization bypass vulnerability
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
Exploit probability
0.1%
Published
July 7, 2026
Required by
Not available
Last source change
July 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
16 explicit affected versions
16 explicit affected versions
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GHSA-jh7c-xh74-h76f
View original source
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
Open Source Vulnerabilities
PYSEC-2026-1899
View original source
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
05 / REFERENCES