CVE-2016-9639: SaltStack Salt

Critical severity, CVSS 9.1. EPSS: 2.6% chance of exploitation in the next 30 days.

Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

Affected products

  • SaltStack Salt: up to and including 2015.8.10

Published 2017-02-07. Last modified 2026-06-17.