Subject: PSA-2026-00065-1: PMG: Bypass DMARC check by spoofed envelope sender header
Advisory date: 2026-10-07
Packages: pmg-api
Details:
Adding a X-Proxmox-Envelope-From header to a mail confuses pmg-smtp-filter into using the mail-address...
Subject: PSA-2026-00064-1: PMG: Administrator to root privilege escalation via private keys in backup
Advisory date: 2026-10-07
Packages: pmg-api
Details:
A user with Administrator role could create and download a backup, which includes the...
Subject: PSA-2026-00062-1: Missing privilege checks when configuring scheduled tape backup jobs
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
A user with sufficient privileges to set up a tape backup job could reference...
Subject: PSA-2026-00061-1: Missing validation of chunk sizes during pull sync
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
An attacker with control over a pull source (or its raw index contents) could trick the pull...
Subject: PSA-2026-00060-1: Missing privilege checks when removing namespace from prune job
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
The required privileges were not checked correctly when removing the configured...
Subject: PSA-2026-00059-1: pxar/container restore target rootfs escape
Advisory date: 2026-10-07
Packages: pve-container, proxmox-backup-client, rust-pxar
Details:
An attacker with direct access to a PBS datastore configured as storage on a...
Subject: PSA-2026-00059-1: pxar/container restore target rootfs escape
Advisory date: 2026-10-07
Packages: pve-container, proxmox-backup-client, rust-pxar
Details:
An attacker with direct access to a PBS datastore configured as storage on a...
Subject: PSA-2026-00058-1: S3-Refresh path escape issue
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
Incomplete validation of an S3 object key returned by a configured S3 endpoint allowed an attacker with control over...
Subject: PSA-2026-00057-1: Missing privilege checks for local sync jobs
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
An attacker with highly privileged access to one datastore + namespace could set up a "local" sync job...
Subject: PSA-2026-00056-1: Missing privilege checks in GC status API
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
Missing privilege checks in the GC status API endpoint at /api2/json/admin/gc/{store} allowed an...
Subject: PSA-2026-00055-1: Incomplete validation of sync encryption/decryption key access
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
An attacker with Datastore.Modify or Datastore.Read on a datastore + namespace can...
Subject: PSA-2026-00054-1: Out-of-bounds read when processing malformed fixed-size index file
Advisory date: 2026-10-07
Packages: proxmox-backup-server
Details:
Missing overflow checks when handling the index and chunk size of a fixed-size...
Subject: PSA-2026-00053-1: PBS backup access includes host/NNN groups
Advisory date: 2026-10-01
Packages: libpve-storage-perl
Details:
If a configured PBS storage contained backup groups with type host, but numerical backup IDs, such...
Subject: PSA-2026-00052-1: Command injection via import of malicious OVA file
Advisory date: 2026-10-01
Packages: libpve-storage-perl, qemu-server
Details:
Insufficient restrictions of OVA member file names allowed an attacker with sufficient...
Subject: PSA-2026-00051-1: integrity bypass of encrypted backups on an untrusted PBS instance
Advisory date: 2026-09-24
Packages: proxmox-backup-client, proxmox-backup-file-restore, libproxmox-backup-qemu0
Details:
When a PBS client is...
Subject: PSA-2026-00051-1: integrity bypass of encrypted backups on an untrusted PBS instance
Advisory date: 2026-09-24
Packages: proxmox-backup-client, proxmox-backup-file-restore, libproxmox-backup-qemu0
Details:
When a PBS client is...
Subject: PSA-2026-00050-1: password change via incomplete username validation
Advisory date: 2026-09-21
Packages: pve-access-control
Details:
An attacker with sufficient privileges to create new PAM user entries (Realm.AllocateUser on...
Subject: PSA-2026-00049-1: PMG: Bypass of mail filters by crafted boundary parameters
Advisory date: 2026-09-21
Packages: pmg-api, libmime-tools-perl
Details:
Certain problematic strings used as Content-Type boundaries were not covered by the...
Subject: PSA-2026-00048-1: PMG: XSS in filename display in attachment quarantine
Advisory date: 2026-09-21
Packages: pmg-gui
Details:
The filename field in the AttachementGrid component shown in the Attachment Quarantine view takes its data...