Junglewise Threat Intelligence

CVE-2026-51083: Proxmox PVE incorrect access control in qemu-server cloudinit/dump API

CVE-2026-51083 · Severity: info · Published 2026-07-17

Vendors: Proxmox.

Executive brief

Proxmox Virtual Environment (PVE) is a platform for managing virtual machines and containers. A security flaw in the server component allows users with restricted access to view sensitive information they should not be able to see. Specifically, an attacker with limited privileges can obtain hashed passwords for virtual machines, which could potentially lead to further unauthorized access if those passwords are cracked.

Technical details

An incorrect access control vulnerability exists in the qemu-server component of Proxmox Virtual Environment (PVE). The flaw is located within the cloudinit/dump API endpoint, which fails to properly restrict access based on user permissions. An authenticated attacker with limited privileges can query this API to retrieve sensitive configuration data, including hashed user passwords. This information disclosure can facilitate offline brute-force attacks to recover plaintext credentials. The issue is resolved in qemu-server versions 9.1.8 (for PVE 9.x) and 8.4.8 (for PVE 8.x).

Affected products

  • Proxmox qemu-server 9.x before 9.1.8, 8.x before 8.4.8

Timeline

  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats