CVE-2020-16846
SaltStack Salt Shell Injection Vulnerability
- Published
- Nov 6, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Nov 3, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Sources
2Docker-based lab environment for exploiting CVE-2020-16846, a shell injection vulnerability in SaltStack Salt API, with step-by-step exploitation instructions and reverse shell payload examples.
- projet-secuExploit
Exploit for CVE-2020-16846 targeting SaltStack with automated vulnerability verification and exploitation capabilities.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.