FlawAtlas
Search the atlas
CVE-2025-22236 High

Salt has minion event bus authorization bypass vulnerability

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

Exploit probability 0.1%
Published July 7, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI salt

16 explicit affected versions

PyPI salt

16 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-jh7c-xh74-h76f

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

View original source
Open Source Vulnerabilities PYSEC-2026-1899

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

View original source

05 / REFERENCES

Further evidence