← Vulnerability feed

Vulnerability record · CVE-2022-22967 · published 23 June 2022

CVE-2022-22967: Saltstack salt incorrect authorization vulnerability

Saltstack · Salt

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

8.8 CVSS 3.1 High EPSS 2.1% · top 18.9% CWE-863 · Incorrect authorization
8.8CVSS 3.1 base score, v2 6.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell accounts with an active session and salt-api users that authenticate via PAM eauth.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22967 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed6.5CVE-2020-11652SaltStack Salt master path traversal in ClearFuncs methodsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 has a path traversal flaw in the salt-master ClearFuncs class, where several methods fail to pr…KEVEPSS 86%analysed10.0CVE-2013-6617Saltstack salt permissions and access controls vulnerabilityThe salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to …EPSS 3.0%10.0CVE-2013-4437Saltstack salt vulnerabilityUnspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."EPSS 1.5%9.8CVE-2021-33226Saltstack salt classic buffer overflow vulnerabilityBuffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/sta…EPSS 1.6%9.8CVE-2021-3148Saltstack salt command injection vulnerabilityAn issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() comman…EPSS 8.2%9.8CVE-2021-3197SaltStack salt-api SSH client shell injection via ProxyCommandSaltStack Salt before 3002.5 contains a shell injection flaw in the salt-api SSH client. An attacker can inject commands by including a ProxyCommand …EPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2022-22967), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.