Known Vulnerabilities for Salt by Saltstack
Listed below are 10 of the newest known vulnerabilities associated with "Salt" by "Saltstack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81717 json | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose t... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-80211 json | FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST[... | Not Provided | 2026-08-27 | 2026-08-29 |
| CVE-2026-80099 json | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-m... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-75106 json | OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowin... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-74889 json | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducin... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-74870 json | openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onl... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-74233 json | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C f... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-72801 json | SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticat... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-70557 json | diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any e... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-57310 json | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who ... | Not Provided | 2026-07-20 | 2026-07-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Saltstack | Salt | 3002.2 | |||
| Application | Saltstack | Salt | 3002.1 | |||
| Application | Saltstack | Salt | 3002 | |||
| Application | Saltstack | Salt | 3001.3 | |||
| Application | Saltstack | Salt | 3001.2 | |||
| Application | Saltstack | Salt | 3001.1 | |||
| Application | Saltstack | Salt | 3001 | |||
| Application | Saltstack | Salt | 3000.3 | |||
| Application | Saltstack | Salt | 3000.2 | |||
| Application | Saltstack | Salt | 3000.13 | |||
| Application | Saltstack | Salt | 3000.1 | |||
| Application | Saltstack | Salt | 3000.0 | |||
| Application | Saltstack | Salt | 3000 | |||
| Application | Saltstack | Salt | 2019.8.0 | |||
| Application | Saltstack | Salt | 2019.2.5 | |||
| Application | Saltstack | Salt | 2019.2.4 | |||
| Application | Saltstack | Salt | 2019.2.3 | |||
| Application | Saltstack | Salt | 2019.2.2 | |||
| Application | Saltstack | Salt | 2019.2.1 | |||
| Application | Saltstack | Salt | 2019.2.0 |