Executive brief
Proxmox Virtual Environment (VE) is a virtualization management platform used to control virtual machines and containers across datacenters. Versions 7.0 through early 8.0 contain an authentication bypass flaw that allows attackers without credentials to log in as any user—including root—by submitting a forged two-factor authentication parameter. This completely bypasses password verification and could give attackers full control of all virtual infrastructure managed by the platform.
Technical details
The vulnerability is an authentication bypass in libpve-access-control affecting versions 7.0-7 through 8.0.3 (fixed in 8.0.4, released 2023-07-20). The API login endpoint (POST /api2/json/access/ticket) accepts a 'tfa-challenge' parameter intended to complete two-factor authentication; however, the parameter was not validated for users without configured second factors, and its mere presence caused password verification to be skipped entirely. An unauthenticated attacker can supply an arbitrary tfa-challenge value to authenticate as any enabled user without second factor configured, gaining full administrative access. The attack requires only network access to the API endpoint; no authentication or user interaction is required. All affected releases are end-of-life; no currently supported version is vulnerable.
Affected products
- Proxmox libpve-access-control 7.0-7 through 8.0.3
Timeline
- 2026-09-01: disclosed: Public security advisory PSA-2026-00043-1 published
- 2023-07-20: patched: libpve-access-control 8.0.4 released with fix