Proxmox Backup Server - Security Advisories

Status
Not open for further replies.

Subject: PSA-2026-00057-1: Missing privilege checks for local sync jobs​


Advisory date: 2026-10-07

Packages: proxmox-backup-server

Details:

An attacker with highly privileged access to one datastore + namespace could set up a "local" sync job pulling from arbitrary datastores.

This issue was discovered internally and independently by Project Loupe.

Fixed in:
- proxmox-backup-server >= 4.2.8-1
 

Subject: PSA-2026-00058-1: S3-Refresh path escape issue​


Advisory date: 2026-10-07

Packages: proxmox-backup-server

Details:

Incomplete validation of an S3 object key returned by a configured S3 endpoint allowed an attacker with control over the S3 server to overwrite arbitrary host paths as user/group backup when an S3-refresh is triggered.

This issue was reported privately by Project Loupe.

Fixed in:
- proxmox-backup-server >= 4.2.7-1
 

Subject: PSA-2026-00059-1: pxar/container restore target rootfs escape​


Advisory date: 2026-10-07

Packages: pve-container, proxmox-backup-client, rust-pxar

Details:

An attacker with direct access to a PBS datastore configured as storage on a Proxmox VE host can construct and upload a malicious pxar archive with two root entries.

When such a backup archive was restored by pve-container, the archive contents were written outside of the target rootfs mountpoint. If a container is restored as privileged container, the extraction runs as root.

proxmox-backup-client will now refuse to follow symlinks during extraction of directories or hardlinks.

This issue was reported privately by Project Loupe.

Fixed in:
- proxmox-backup-client >= 4.2.7-1
 

Subject: PSA-2026-00060-1: Missing privilege checks when removing namespace from prune job​


Advisory date: 2026-10-07

Packages: proxmox-backup-server

Details:

The required privileges were not checked correctly when removing the configured namespace from an existing prune job.

This issue was reported privately by Project Loupe.

Fixed in:
- proxmox-backup-server >= 4.2.8-1
 

Subject: PSA-2026-00061-1: Missing validation of chunk sizes during pull sync​


Advisory date: 2026-10-07

Packages: proxmox-backup-server

Details:

An attacker with control over a pull source (or its raw index contents) could trick the pull target into storing an index file with an invalid reference to a valid chunk. Subsequent verification of that index will treat the chunk as corrupt, breaking availability of other valid snapshots referencing it.

This issue was reported privately by Project Loupe.

Fixed in:
- proxmox-backup-server >= 4.2.8-1
 

Subject: PSA-2026-00062-1: Missing privilege checks when configuring scheduled tape backup jobs​


Advisory date: 2026-10-07

Packages: proxmox-backup-server

Details:

A user with sufficient privileges to set up a tape backup job could reference any datastore or tape media pool/drive in the created job config.

This issue was reported privately by Project Loupe.

Fixed in:
- proxmox-backup-server >= 4.2.7-1
 
Status
Not open for further replies.