CVE-2025-62349: Salt Project Salt

Medium severity, CVSS 6.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

Affected products

  • Salt Project Salt: from 3006.12, before 3006.17 (fixed in 3006.17); from 3007.4, before 3007.9 (fixed in 3007.9)

Published 2026-01-30. Last modified 2026-06-17.