SaltStack Salt Shell Injection Vulnerability

Added to KEV
2021-11-03
Federal due date
2022-05-03
Vendor
SaltStack
Product
Salt
EPSS
100.0th percentile (score 0.944, as of 2026-06-08)
NVD CVSS v3.1
Ransomware use
Unknown
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2020-16846

CISA short description

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

Required action

Apply updates per vendor instructions.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.