New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
PSA: Update your Proxmox VE installations (Authentication bypass in EOL Proxmox VE releases)
https://forum.proxmox.com/posts/867929/
TL;DR:
- Older, EOL versions of Proxmox VE have an actively exploited vulnerability with the
libpve-access-controlpackage (Affected: >= 7.0-7 and < 8.0.4) - If 8006 WebUI/API is exposed to public Internet, attackers can bypass passwords entirely to authenticate as root, due to a cursed 2FA implementation
- Current supported PVE versions (9.x) are completely safe
- If you are still running PVE 7.x-8.0.3, restrict access to port 8006 and upgrade immediately

Comments
I was one of the original reporters in the advisory.
Sharing my repo with the fixes, root cause analysis, and detection rules: https://github.com/neeythann/Proxmox-VE-7-RCE
@trumvps is this what you mentioned?
oh, it doesn't affect much anyway
edit: okay chatgpt scheduled task just sent me an update, which the api /access/ticket can be bypassed completely