Vulnerability record · CVE-2021-25281 · published 27 February 2021
CVE-2021-25281: SaltStack salt-api authentication bypass in wheel_async client
Saltstack · Salt
SaltStack Salt before 3002.5 has an improper authentication flaw in salt-api: the wheel_async client does not honor eauth credentials. An unauthenticated remote attacker can therefore invoke arbitrary wheel modules on the Salt master, which is a high-value control node.
Description
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and very high EPSS, against a master node that controls the whole fleet.
What it is
SaltStack Salt before 3002.5 has an improper authentication flaw in salt-api: the wheel_async client does not honor eauth credentials. An unauthenticated remote attacker can therefore invoke arbitrary wheel modules on the Salt master, which is a high-value control node.
Impact
An attacker gains unauthenticated remote execution of wheel modules on the Salt master, effectively full control of the master and, through it, the managed minion fleet.
Attack surface
Reachable over the network via the salt-api service; the CVSS vector shows no privileges required and no user interaction, and the description states the eauth check is not enforced for wheel_async.
Exploitation
Not listed in CISA KEV, but EPSS is 0.7313 (99.4th percentile) and a public Packet Storm exploit reference exists, indicating active interest and available exploit code.
What to do
- Upgrade Salt to 3002.5 or later, or apply the vendor patch from the February 2021 SaltStack security release.
- If salt-api is not required, disable it; otherwise restrict network access to the salt-api port to trusted management hosts only.
- Rotate any credentials and secrets reachable from the Salt master, since wheel modules can alter master configuration and keys.
- Audit master configuration and minion keys for unauthorized changes made through wheel modules.
- Track distribution advisories (Debian DSA-5011, Fedora, Gentoo GLSA) for packaged fixes.
Detection
- Monitor salt-api logs for wheel_async or wheel module invocations from unexpected source addresses.
- Alert on new or modified Salt master configuration, pillar, or key files outside change windows.
- Baseline and review salt-api authentication failures and unusual API request patterns.
- Watch for unexpected minion key acceptances or command execution across the fleet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-25281 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25281), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.