{"cve":"CVE-2023-54391","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[7.0,7.4]"}},{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"8.0"}}],"enrichment":{"confidence":100.0,"confidence_source":"manual","scores":[{"score":100.0,"source":"manual"}]},"original":{"product":"Proxmox Virtual Environment (VE)","source":"cna","vendor":"Proxmox Server Solutions GmbH"},"product":"proxmox_virtual_environment_(ve)","vendor":"proxmox"}],"created":"2026-09-01T23:30:05.340728+00:00","updated":"2026-09-05T15:30:17.506361+00:00","vendors":["proxmox","proxmox$PRODUCT$proxmox_virtual_environment_(ve)"]},"epss":{"score":0.03031},"mitre":{"cpes":[],"created":"2026-09-01T21:59:12.692000+00:00","description":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2023/54xxx/CVE-2023-54391.json","references":["https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=0f3d14d6be4d9f23e511701696a529ef3b7ffd61","https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter"],"title":"Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter","updated":"2026-09-03T14:28:03.483000+00:00","vendors":[],"weaknesses":["CWE-304"]},"nvd":{"cpes":[],"created":"2026-09-01T22:17:10.283000+00:00","description":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2023/CVE-2023-54391.json","references":["https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=0f3d14d6be4d9f23e511701696a529ef3b7ffd61","https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter"],"title":null,"updated":"2026-09-08T20:18:59.270000+00:00","vendors":[],"weaknesses":["CWE-304"]},"opencve":{"changes":[{"created":"2026-09-01T22:00:00+00:00","data":[{"details":{"new":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.","old":null},"type":"description"},{"details":{"new":"Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter","old":null},"type":"title"},{"details":{"added":["CWE-304"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022","https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b351d670-1ca1-4d71-8694-33e1d6417d1f"},{"created":"2026-09-02T12:45:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"aa768b8b-aa91-4c80-8f82-d53f9c9aa45d"},{"created":"2026-09-02T17:30:00+00:00","data":[{"details":["proxmox","proxmox$PRODUCT$proxmox_virtual_environment_(ve)"],"type":"first_time"},{"details":{"added":["proxmox","proxmox$PRODUCT$proxmox_virtual_environment_(ve)"],"removed":[]},"type":"vendors"}],"id":"8cd128fb-63ce-432e-9e10-7cf81a4b69cb"},{"created":"2026-09-03T14:45:00+00:00","data":[{"details":{"added":["https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=0f3d14d6be4d9f23e511701696a529ef3b7ffd61"],"removed":[]},"type":"references"}],"id":"d12651e9-d91b-48a1-bac7-42edcfcceab2"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-01T21:59:12.692000+00:00","provider":"mitre"},"description":{"data":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.03031},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022","https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=0f3d14d6be4d9f23e511701696a529ef3b7ffd61","https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter"],"providers":["mitre","nvd"]},"title":{"data":"Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter","provider":"mitre"},"updated":{"data":"2026-09-03T14:28:03.483000+00:00","provider":"mitre"},"vendors":{"data":["proxmox","proxmox$PRODUCT$proxmox_virtual_environment_(ve)"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-304"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-01T21:59:12.692000+00:00","description":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter","updated":"2026-09-02T11:56:14.034000+00:00","vendors":[],"vulnrichment_repo_path":"2023/54xxx/CVE-2023-54391.json","weaknesses":[]}}