{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/proxmox-backup-server--3.2.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sukiwp:suki_sites_import:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.4,"id":"CVE-2024-8916"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Proxmox Backup Server (\u003c 3.2.7)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Proxmox"],"content_html":"\u003cp\u003eProxmox Backup Server versions prior to 3.2.7 are affected by a security vulnerability identified as CVE-2024-8916. This flaw arises from insufficient access controls within the backup server's architecture, allowing a local attacker with authenticated access to manipulate files and perform unauthorized information disclosure. The vulnerability impacts the integrity and confidentiality of the backup data stored on affected systems. Administrators are advised to update their Proxmox Backup Server installations to version 3.2.7 or later to mitigate this risk. This is a critical concern for environments relying on Proxmox for data protection, as the compromise of the backup infrastructure could lead to broader organizational exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability allows unauthorized users to modify or access sensitive backup data. Given the role of Proxmox Backup Server in centralizing organization-wide backups, this flaw poses a significant risk to data integrity and long-term recovery capabilities, potentially impacting any sector currently utilizing versions older than 3.2.7.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all Proxmox Backup Server instances to version 3.2.7 or higher immediately to address CVE-2024-8916.\u003c/li\u003e\n\u003cli\u003eAudit existing local user permissions and access rights on the host operating system to identify and limit accounts capable of interacting with the backup storage directories.\u003c/li\u003e\n\u003cli\u003eMonitor system logs for unauthorized access or modification attempts within the directories used by the Proxmox Backup Server daemon.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:08:00Z","date_published":"2026-08-14T14:08:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-proxmox-backup-server-vulnerability/","summary":"Proxmox Backup Server contains a vulnerability (CVE-2024-8916) that allows a local attacker to manipulate files and disclose sensitive information due to improper access controls.","title":"Proxmox Backup Server Information Disclosure and File Manipulation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-proxmox-backup-server-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Proxmox Backup Server (\u003c 3.2.7)","version":"https://jsonfeed.org/version/1.1"}