{"id":"PYSEC-2026-1902","summary":"Salt Authentication Protocol Version Downgrade Allows Minion Impersonation","details":"Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.","aliases":["CVE-2025-62349","GHSA-vcf3-26xf-fw4m"],"modified":"2026-07-07T17:48:09.469233771Z","published":"2026-07-07T16:03:21.156662Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62349"},{"type":"WEB","url":"https://github.com/saltstack/salt/issues/68467"},{"type":"WEB","url":"https://github.com/saltstack/salt/commit/3d5708acae16d039a1e2b5529c8e14a0d3255611"},{"type":"WEB","url":"https://docs.saltproject.io/en/latest/topics/releases/3006.17.html"},{"type":"WEB","url":"https://docs.saltproject.io/en/latest/topics/releases/3007.9.html"},{"type":"PACKAGE","url":"https://github.com/saltstack/salt"},{"type":"PACKAGE","url":"https://pypi.org/project/salt"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vcf3-26xf-fw4m"}],"affected":[{"package":{"name":"salt","ecosystem":"PyPI","purl":"pkg:pypi/salt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3006.12"},{"fixed":"3006.17"},{"introduced":"3007.4"},{"fixed":"3007.9"}]}],"versions":["3006.12","3006.13","3006.14","3006.15","3006.16","3007.4","3007.5","3007.6","3007.7","3007.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/salt/PYSEC-2026-1902.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}