Proxmox · Proxmox Virtual Environment · CVE-2023-54391
**Name of the Vulnerable Software and Affected Versions**
Proxmox Virtual Environment (VE) versions 7.0 through 8.0
**Description**
An authentication bypass exists in libpve-access-control that allows unauthenticated attackers to authenticate as any enabled user who does not have a second factor configured. By sending a POST request to the access ticket API endpoint with an arbitrary value in the `tfa-challenge` parameter, an attacker can skip password verification and gain unauthorized access, including access to the `root@pam` account.
**Recommendations**
Update libpve-access-control to version 8.0.4 or later.