CVE-2026-94588: CSRF

Published Sep 21, 2026
·
Updated

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.

Affected Software

1 affected component
Proxmox pmg-api

Event History

Sep 21, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires an authenticated user with high privileges. The vulnerable functionality can also be targeted through a CSRF-style attack, so a privileged authenticated user may be induced to trigger it.

2

What conditions are needed for exploitation?

An attacker must be able to supply input to the package changelog retrieval functionality and have that input reach the underlying apt-get command. The attack complexity is rated high, and no user interaction is required by the CVSS vector.

3

What is the potential impact?

Successful exploitation can affect confidentiality and integrity at a low level, with scope changed. No availability impact is indicated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203