FAIL › dossier
SaltStack
VENDOR· dossier confidence 20%
SaltStack's core automation platform suffered multiple high-severity remote code execution and path traversal flaws in 2020, allowing unauthenticated attackers to execute arbitrary commands and access sensitive data. These vulnerabilities highlight critical gaps in input validation and access control within the product's API and authentication layers.
PROFILE
CategoryautomationWhat they doSaltStack provides an open-source automation platform for system configuration management and orchestration.
Websitehttps://saltstack.com ↗
SECURITY POSTURE
The company has a history of critical remote code execution (RCE) and path traversal vulnerabilities in its core product, highlighting gaps in input validation and access control within the API and authentication layers.
Notable failures
- CVE-2020-11651: unauthenticated RCE via ClearFuncs
- CVE-2020-16846: unauthenticated shell injection RCE
- CVE-2020-11652: authenticated path traversal for arbitrary file read
Patterns: repeated unpatched edge-device RCEs; insufficient input validation in API layers; weak access control in authentication mechanisms
Reputationneutral (-0.11) · 9 trusted sources
CoverageCISA · cooey · cooey · cooey · www.arista.com · www.cvefind.com
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-11651 | high | SaltStack Salt's improperly validated ClearFuncs method calls allowed unauthenticated remote access to tokens and command execution on minions. |
| 2021-11-03 | CVE-2020-16846 | high | An unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection. |
| 2021-11-03 | CVE-2020-11652 | high | SaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
synthesisneutral-0.20
Vulnerability disclosed with standard mitigation guidance; no severe fallout or praise.
synthesisneutral-0.20
Vulnerability disclosed; no direct press coverage or authority condemnation found in provided sources.
No relevant content; Dell support page.
No relevant content; CVE database site.
No relevant content; Arista advisories page.
No relevant content; Local news article.
No relevant content; CVE database site.
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client."
Neutral disclosure with standard mitigation guidance.
"SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
Neutral disclosure; notes best practices mitigate risk.
"Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
No relevant content; generic CISA page.
DOSSIER SOURCES
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- Phasmophobia Patches and Updates · SteamDB · steamdb.info
- Nvd - Cve-2026-11861 · NVD
Open questions: current patch status for CVE-2020-11651/16846/11652 · whether SaltStack has implemented a bug bounty program to improve vulnerability disclosure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:48:42.401406+00:00