Vulnerability record · CVE-2020-16846 · published 6 November 2020
CVE-2020-16846: SaltStack Salt API shell injection via crafted web requests
Saltstack · Salt
SaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. The flaw is a CWE-78 shell injection reachable over the network without authentication, and it carries a CVSS 3.1 base score of 9.8 (critical).
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable command injection with a 9.8 CVSS score, KEV listing and near-maximum EPSS probability makes this an urgent patch target.
What it is
SaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. The flaw is a CWE-78 shell injection reachable over the network without authentication, and it carries a CVSS 3.1 base score of 9.8 (critical).
Impact
An unauthenticated remote attacker can execute arbitrary shell commands on the Salt master, leading to full compromise of the host and any managed infrastructure it controls.
Attack surface
Reached over the network through the Salt API when the SSH client is enabled; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.
Exploitation
CISA added it to KEV on 2021-11-03 with a remediation due date of 2022-05-03, and EPSS shows a 30-day probability of 0.99585 (99.946th percentile); reference tags include an Exploit entry, indicating public exploit material exists. No ransomware campaign use is documented.
What to do
- Apply vendor updates for SaltStack Salt and the affected Debian, Fedora and openSUSE packages per vendor instructions.
- If patching cannot be done immediately, disable the Salt API SSH client or restrict Salt API exposure to trusted networks.
- Place the Salt API behind authentication and network access controls; do not expose it directly to untrusted networks.
- Monitor vendor advisories for the affected distributions and confirm the installed Salt version is above 3002.
Detection
- Inspect Salt API access logs for crafted or anomalous requests, especially those invoking SSH client functionality.
- Monitor for unexpected child processes spawned by the Salt master or salt-api service.
- Alert on outbound network connections or command execution originating from Salt master hosts.
- Review Salt configuration to confirm whether the SSH client is enabled and whether the API is externally reachable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-16846 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SaltStack Salt Shell Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-16846 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-16846), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.