{"id":"CVE-2025-22236","aliases":["PYSEC-2026-1899"],"url":"https://o3.security/vulnerability/CVE-2025-22236","summary":"Salt has minion event bus authorization bypass vulnerability","details":"Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).","published":"2025-06-13T09:30:33Z","modified":"2026-07-07T17:56:27.645577509Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"salt","fixedVersion":"3007.4"},{"ecosystem":"PyPI","name":"salt","fixedVersion":"3006.12"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22236"},{"type":"WEB","url":"https://docs.saltproject.io/en/3006/topics/releases/3006.12.html"},{"type":"WEB","url":"https://docs.saltproject.io/en/3007/topics/releases/3007.4.html"},{"type":"PACKAGE","url":"https://github.com/saltstack/salt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:27.645577509Z"}}