SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-54391

CRITICAL · CVSS 9.8 EPSS 1.75%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Proxmox Virtual Environment versions 7.0 through 8.0 are vulnerable to an authentication bypass flaw that allows unauthenticated attackers to gain access as any enabled user, including root, by manipulating the tfa-challenge parameter in the API login endpoint. This critical vulnerability poses a severe risk of unauthorized access to sensitive systems and data. Organizations using affected versions should prioritize immediate remediation, as all impacted releases are no longer supported.

CVE
CVE-2023-54391
Severity
CRITICAL
CVSS
9.8
EPSS
1.75%

Original NVD Description

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.