PatchSiren cyber security CVE debrief
CVE-2016-9639 Saltstack CVE debrief
CVE-2016-9639 is a critical access-control issue in Salt affecting versions before 2015.8.11. According to the CVE description, deleted minions could read from or write to other minions that later reused the same ID, with the problem tied to caching. In practice, that means minion identity reuse could expose data or permit unintended state changes across machines that share an identifier over time.
- Vendor
- Saltstack
- Product
- Salt
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-07
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-07
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams running Salt masters and minions, especially environments where minion IDs may be reused, hosts are rebuilt frequently, or caching and identity lifecycle controls are part of the operational model.
Technical summary
NVD maps this issue to CWE-284 (Improper Access Control) and rates it CVSS 3.0 9.1 Critical. The vulnerable range is Salt versions up to and including 2015.8.10. The core failure is that cached authorization or identity state could persist after a minion was deleted, allowing a later minion with the same ID to inherit access that should no longer exist. The CVE references Salt documentation for rotating the AES key as part of the vendor guidance context.
Defensive priority
Immediate. This is network-reachable, requires no user interaction, and can affect confidentiality and integrity. Systems still on affected Salt releases should be prioritized for upgrade and configuration review.
Recommended defensive actions
- Upgrade Salt to 2015.8.11 or later.
- Audit environments for minion ID reuse, especially after rebuilds, deprovisioning, or cloning.
- Review master-side caching and access-control behavior for stale identity state.
- Follow the vendor guidance referenced by NVD, including Salt master configuration documentation related to rotating the AES key.
- Check whether any automation, orchestration, or secrets distribution workflows depend on assumptions about persistent minion identity.
Evidence notes
All statements here are grounded in the supplied CVE and NVD metadata: the issue description says deleted minions can read or write to minions with the same ID and ties the behavior to caching; NVD marks the vulnerability as affecting Salt through 2015.8.10 and assigns CWE-284 with CVSS 3.0 9.1 Critical. The published date used for context is 2017-02-07, and the 2026-05-13 timestamp reflects record modification, not the vulnerability date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9639 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9639
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9639 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9639
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://docs.saltstack.com/en/2015.8/ref/configuration/master.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.