An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence91%
Public exploitation · VTP factUNKNOWN
Assessment
Salt before 3002.5 fails to honor eauth credentials for the wheel_async client, allowing a remote attacker to run arbitrary wheel modules on the master. The supplied CVSS is 9.8 with complete confidentiality, integrity, and availability impact. EPSS is elevated at 0.7313, but no exploitation evidence is supplied.
Why it matters
Control of wheel modules on the Salt master could compromise centralized infrastructure administration.
The supplied vector requires neither privileges nor user interaction.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The bundle does not establish salt-api exposure, deployed versions, or configuration.
No KEV entry, exploit evidence, or first-party telemetry is supplied; EPSS is predictive only.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Identify Salt versions before 3002.5 and externally reachable salt-api services.
AI baseline history (1)
BASELINE ASSESSED
Salt-API wheel_async authentication bypassgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.73; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.