Description
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.
Published: 2026-09-01
Score: 9.3 Critical
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Proxmox
Proxmox proxmox Virtual Environment (ve)
Vendors & Products Proxmox
Proxmox proxmox Virtual Environment (ve)

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.
Title Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
Weaknesses CWE-304
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Proxmox Proxmox Virtual Environment (ve)
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T14:28:03.483Z

Reserved: 2026-09-01T21:23:55.860Z

Link: CVE-2023-54391

cve-icon Vulnrichment

Updated: 2026-09-02T11:56:14.034Z

cve-icon NVD

Status : Received

Published: 2026-09-01T22:17:10.283

Modified: 2026-09-03T15:17:16.213

Link: CVE-2023-54391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T15:30:17Z

Weaknesses