Subject: PSA-2026-00043-1: Authentication bypass in EOL Proxmox VE 7 release
Advisory date: 2026-09-01
Packages: libpve-access-control
Affected: libpve-access-control >= 7.0-7 and < 8.0.4
Roughly corresponding to Proxmox VE 7.0 up to and including 7.4 (end of life since July 2024), and, for completeness, the initial Proxmox VE 8.0 (EOL), as the fix only shipped roughly one month after that release.
Package versions and the overall Proxmox VE version only correlate loosely, since dependency versions are only raised when needed. To determine whether an...
The vulnerable code path was closed in July 2023, ... At that time, the authentication bypass was not known: the rework was not a security fix, and the issue had neither been found internally nor reported. It was therefore not recognized as a candidate for a backport to the PVE 7 branch.
Last edited: