CVE-2016-3176: SaltStack Salt

Medium severity, CVSS 5.6. EPSS: 0.9% chance of exploitation in the next 30 days.

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Affected products

  • SaltStack Salt: up to and including 2015.5.9; version 2015.8.0 only; version 2015.8.1 only; version 2015.8.2 only; version 2015.8.3 only; version 2015.8.4 only; …

Published 2017-01-31. Last modified 2026-06-17.