CRITICAL
Proxmox Server Solutions GmbH
CVE published 2026-09-01
CVE-2023-54391
CVE-2023-54391 is a critical authentication bypass vulnerability in Proxmox Virtual Environment (VE) 7.0 through 8.0, existing in libpve-access-control before version 8.0.4. This vulnerability allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. The vulnerability has a CVSS [truncated]