CVE-2025-22236: VMware Salt

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

Affected products

  • VMware Salt: from 3006, before 3006.12 (fixed in 3006.12); from 3007, before 3007.4 (fixed in 3007.4)

Published 2025-06-13. Last modified 2026-06-17.