Proxmox Backup Server Information Disclosure and File Manipulation Vulnerability
Proxmox Backup Server contains a vulnerability (CVE-2024-8916) that allows a local attacker to manipulate files and disclose sensitive information due to improper access controls.
CVE search metadata
CVE search record: CVE-2024-8916. Severity: medium. CVSS: 6.4. EPSS: 0.28%. KEV: no. Product: Proxmox Backup Server (< 3.2.7). Brief: Proxmox Backup Server Information Disclosure and File Manipulation Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-08-proxmox-backup-server-vulnerability/
Proxmox Backup Server versions prior to 3.2.7 are affected by a security vulnerability identified as CVE-2024-8916. This flaw arises from insufficient access controls within the backup server's architecture, allowing a local attacker with authenticated access to manipulate files and perform unauthorized information disclosure. The vulnerability impacts the integrity and confidentiality of the backup data stored on affected systems. Administrators are advised to update their Proxmox Backup Server installations to version 3.2.7 or later to mitigate this risk. This is a critical concern for environments relying on Proxmox for data protection, as the compromise of the backup infrastructure could lead to broader organizational exposure.
Impact
The successful exploitation of this vulnerability allows unauthorized users to modify or access sensitive backup data. Given the role of Proxmox Backup Server in centralizing organization-wide backups, this flaw poses a significant risk to data integrity and long-term recovery capabilities, potentially impacting any sector currently utilizing versions older than 3.2.7.
Recommendation
- Update all Proxmox Backup Server instances to version 3.2.7 or higher immediately to address CVE-2024-8916.
- Audit existing local user permissions and access rights on the host operating system to identify and limit accounts capable of interacting with the backup storage directories.
- Monitor system logs for unauthorized access or modification attempts within the directories used by the Proxmox Backup Server daemon.
Immediate actions
Patch Proxmox Backup Server to version 3.2.7 or higher.