CVE-2023-54391: Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter

Published Sep 1, 2026
·
Updated

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

Affected Software

1 affected component
Proxmox Proxmox VE>=7.0<8.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Proxmox VE to a version that resolves this vulnerability.

    Fixed in 8.0.4
  2. Compensating control

    Block access to the Proxmox VE API login/access ticket endpoint from untrusted networks (e.g., restrict management/API traffic via firewall/ACL/WAF) until the fixed version is applied.

Event History

Sep 1, 2026
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which accounts can an attacker impersonate?

An unauthenticated attacker can authenticate as any existing enabled user that does not have a configured second factor. This includes root@pam if that account is enabled and has no second factor configured.

2

What does an attacker need to exploit this issue?

The attacker only needs network access to the API login endpoint and can submit a POST request containing an arbitrary tfa-challenge parameter. No valid credentials or user interaction are required.

3

Are installations with second-factor authentication protected?

The bypass applies to existing enabled users without a configured second factor. Accounts with a configured second factor are not identified as affected by the provided information.

4

Which versions contain the vulnerable component?

The issue affects Proxmox VE 7.0 through 8.0 where libpve-access-control is earlier than 8.0.4. The supplied data states that all affected releases are end of life.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203