CVE-2018-15751: Critical severity SaltStack Salt vulnerability
Last updated 25 August 2025
Other sources
SaltStack Salt 2016.11.x before 2016.11.10, 2017.7.x before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
— GitHub
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2018.3.3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 2018.3.3
Event History
Frequently Asked Questions
What is CVE-2018-15751?
CVE-2018-15751 is a vulnerability in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 that allows remote attackers to bypass authentication and execute arbitrary commands.
What is the severity of CVE-2018-15751?
The severity of CVE-2018-15751 is critical with a severity score of 9.8.
How can I fix CVE-2018-15751?
To fix CVE-2018-15751, update SaltStack Salt to version 2017.7.8 or newer for the 2017.7.x branch, or update to version 2018.3.3 or newer for the 2018.3.x branch.
Where can I find more information about CVE-2018-15751?
You can find more information about CVE-2018-15751 in the following references: [CVE-2018-15751 on MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15751), [SaltStack Salt 2017.7.8 Release Notes](https://docs.saltstack.com/en/2017.7/topics/releases/2017.7.8.html), [SaltStack Salt 2018.3.3 Release Notes](https://docs.saltstack.com/en/latest/topics/releases/2018.3.3.html).
What is the Common Weakness Enumeration (CWE) number of CVE-2018-15751?
The Common Weakness Enumeration (CWE) number of CVE-2018-15751 is CWE-287.