CVE-2018-15751: SaltStack Salt

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

Affected products

  • SaltStack Salt: before 2017.7.8 (fixed in 2017.7.8); from 2018.3.0, before 2018.3.3 (fixed in 2018.3.3)

Published 2018-10-24. Last modified 2026-06-17.