CVE-2025-62349
Severity CVSS v4.0:
HIGH
Type:
CWE-287
Authentication Issues
Publication date:
30/01/2026
Last modified:
30/01/2026
Description
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.
Impact
Base Score 4.0
7.50
Severity 4.0
HIGH
Base Score 3.x
6.20
Severity 3.x
MEDIUM



