PatchSiren

Proxmox Server Solutions GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Proxmox Server Solutions GmbH CVE published 2026-09-01

CVE-2023-54391

CVE-2023-54391 is a critical authentication bypass vulnerability in Proxmox Virtual Environment (VE) 7.0 through 8.0, existing in libpve-access-control before version 8.0.4. This vulnerability allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. The vulnerability has a CVSS [truncated]