Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2023-54391: Proxmox VE 7‑8 lets attackers log in without password

CVE-2023-54391 · published 1 day ago
Summary

Versions 7.0 through 8.0 of Proxmox Virtual Environment let an unauthenticated user skip the normal password check and log in as any enabled account, including the powerful root account. This happens when a specially crafted login request includes an arbitrary two‑factor value. Upgrade to the latest Proxmox release (or apply the vendor's patch) as soon as possible to restore proper authentication.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
proxmox server solutions gmbh proxmox virtual environment (ve) <= 7.4
Original advisory text
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any e...
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Type
CWE-304Missing Critical Step in Authentication
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2023-54391 · MITRE
Monitor software like this
Free during beta