Junglewise Threat Intelligence

CVE-2026-94588: Proxmox Mail Gateway argument injection in package changelog retrieval

CVE-2026-94588 · Severity: medium · CVSS 4.4 · Published 2026-09-21

Vendors: Proxmox.

Executive brief

Proxmox Mail Gateway's API contains a vulnerability in its package changelog retrieval functionality that allows argument injection attacks. An authenticated attacker can exploit this to inject malicious arguments into system commands, potentially leading to unauthorized command execution or information disclosure. While authentication is required, the vulnerability can be leveraged in CSRF-style attacks against administrative users.

Technical details

The vulnerability exists in pmg-api's package changelog endpoint where user-supplied input is insufficiently sanitized before being passed to underlying apt-get commands. An authenticated attacker can inject shell arguments to alter command behavior. The attack vector requires prior authentication but does not require explicit user interaction beyond normal API access.

Affected products

  • Proxmox Mail Gateway pmg-api <UNKNOWN>

Timeline

  • 2026-09-21: disclosed

References