Skip to content
Threat Feed
critical advisory

Authentication Bypass in Proxmox Virtual Environment

CVE-2023-54391 allows unauthenticated remote attackers to bypass authentication in Proxmox VE 7.0-8.0 by providing a crafted tfa-challenge parameter to the API login endpoint.

CVE search metadata

CVE search record: CVE-2023-54391. Severity: critical. CVSS: 9.8. KEV: no. Product: Proxmox Virtual Environment (7.0 - 8.0). Brief: Authentication Bypass in Proxmox Virtual Environment. Brief link: https://feed.craftedsignal.io/briefs/2026-09-proxmox-auth-bypass/

CVE-2023-54391 is an authentication bypass vulnerability affecting the Proxmox Virtual Environment (VE) 7.0 through 8.0, specifically within the libpve-access-control component versions prior to 8.0.4. The vulnerability stems from improper validation of the tfa-challenge parameter during the API login process. An unauthenticated attacker can supply an arbitrary value in this parameter to successfully authenticate as any enabled user, including the root account (root@pam), provided that user does not have a second factor configured. Successful exploitation results in full administrative control over the hypervisor and managed virtual machine environments. As all affected versions are documented as end-of-life, defenders must prioritize identifying vulnerable instances and migrating to supported versions, as patches for these specific releases may not be available.

Impact

Successful exploitation allows for complete, unauthenticated administrative access to the Proxmox VE management interface. This permits the attacker to execute arbitrary code, manipulate virtual machines, access sensitive guest data, and potentially pivot into the underlying network infrastructure hosting the hypervisor.

Recommendation

Prioritize the identification of internet-facing Proxmox VE instances running version 8.0.3 or earlier. Given that these versions are end-of-life, the primary mitigation is immediate migration to a supported, patched version of Proxmox VE. Monitor web server logs for high volumes of POST requests to the API ticket endpoint originating from unauthorized IP addresses, specifically looking for abnormal usage of the tfa-challenge parameter.


Immediate actions

Inventory all internet-facing Proxmox VE instances

SOC 24h

Mitigations

Upgrade Proxmox VE to a supported version beyond 8.0.4

immediate IT Operations

CVE-2023-54391

Detection coverage 1

Detects CVE-2023-54391 Exploitation - Unauthorized API Access

critical

Detects exploitation attempts where an unauthenticated user provides a tfa-challenge parameter to the Proxmox login API

sigma tactics: initial_access techniques: T1550.002 sources: webserver

Detection queries are available on the platform. Get full rules →