CVE-2026-94588: CSRF
In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated user with high privileges. The vulnerable functionality can also be targeted through a CSRF-style attack, so a privileged authenticated user may be induced to trigger it.
What conditions are needed for exploitation?
An attacker must be able to supply input to the package changelog retrieval functionality and have that input reach the underlying apt-get command. The attack complexity is rated high, and no user interaction is required by the CVSS vector.
What is the potential impact?
Successful exploitation can affect confidentiality and integrity at a low level, with scope changed. No availability impact is indicated.