---
id: CVE-2023-54391
title: >-
  Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication
  bypass vulnerability in libpve-access-control before 8.0.4 that allows
  unauthenticated attackers to authenticate as any existing enabled user without
  a configure…
summary: >-
  Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication
  bypass vulnerability in libpve-access-control before 8.0.4 that allows
  unauthenticated attackers to authenticate as any existing enabled user without
  a configure…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-304
published: '2026-09-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54391'
references:
  - url: >-
      https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929
    label: disclosure@vulncheck.com
  - url: >-
      https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022
    label: disclosure@vulncheck.com
  - url: >-
      https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022
    label: disclosure@vulncheck.com
  - url: >-
      https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022
    label: disclosure@vulncheck.com
  - url: >-
      https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=032e7d6d441f89a48cadfd7f47e957c8a561c022
    label: disclosure@vulncheck.com
  - url: >-
      https://git.proxmox.com/?p=pve-access-control.git;a=commit;h=0f3d14d6be4d9f23e511701696a529ef3b7ffd61
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/proxmox-ve-authentication-bypass-via-tfa-challenge-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
epss: 0.03031
epssPercentile: 0.86957
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/disqualifier/psa-2026-00043-recovery'
  nuclei:
    - CVE-2023-54391
  checkedAt: '2026-09-26T09:05:35.302Z'
exploitAvailable: true
ingestedAt: '2026-09-08T21:11:12.289Z'
---

## Overview

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
