Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life. | |
| Title | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter | |
| Weaknesses | CWE-304 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T11:59:20.773Z
Reserved: 2026-09-01T21:23:55.860Z
Link: CVE-2023-54391
Updated: 2026-09-02T11:56:14.034Z
Status : Received
Published: 2026-09-01T22:17:10.283
Modified: 2026-09-02T12:17:10.557
Link: CVE-2023-54391
No data.
OpenCVE Enrichment
Updated: 2026-09-01T23:30:05Z