<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:proxmox:virtual_environment:7.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aproxmoxvirtual_environment7.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 23:09:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aproxmoxvirtual_environment7.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Proxmox Virtual Environment</title><link>https://feed.craftedsignal.io/briefs/2026-09-proxmox-auth-bypass/</link><pubDate>Tue, 01 Sep 2026 23:09:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-proxmox-auth-bypass/</guid><description>CVE-2023-54391 allows unauthenticated remote attackers to bypass authentication in Proxmox VE 7.0-8.0 by providing a crafted tfa-challenge parameter to the API login endpoint.</description><content:encoded><![CDATA[<p>CVE-2023-54391 is an authentication bypass vulnerability affecting the Proxmox Virtual Environment (VE) 7.0 through 8.0, specifically within the libpve-access-control component versions prior to 8.0.4. The vulnerability stems from improper validation of the tfa-challenge parameter during the API login process. An unauthenticated attacker can supply an arbitrary value in this parameter to successfully authenticate as any enabled user, including the root account (root@pam), provided that user does not have a second factor configured. Successful exploitation results in full administrative control over the hypervisor and managed virtual machine environments. As all affected versions are documented as end-of-life, defenders must prioritize identifying vulnerable instances and migrating to supported versions, as patches for these specific releases may not be available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete, unauthenticated administrative access to the Proxmox VE management interface. This permits the attacker to execute arbitrary code, manipulate virtual machines, access sensitive guest data, and potentially pivot into the underlying network infrastructure hosting the hypervisor.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of internet-facing Proxmox VE instances running version 8.0.3 or earlier. Given that these versions are end-of-life, the primary mitigation is immediate migration to a supported, patched version of Proxmox VE. Monitor web server logs for high volumes of POST requests to the API ticket endpoint originating from unauthorized IP addresses, specifically looking for abnormal usage of the tfa-challenge parameter.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>critical</category></item></channel></rss>