SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-51082

HIGH · CVSS 7.2 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A race condition vulnerability in the Proxmox Virtual Environment allows an authenticated attacker with access to the "vncproxy" API to hijack VNC sessions of other users connected to different virtual machines. This could lead to unauthorized access to sensitive data or control over the affected VMs. Organizations using affected versions of Proxmox should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-51082
Severity
HIGH
CVSS
7.2
EPSS
0.22%

Original NVD Description

A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.