PROXMOX has issued an advisory regarding a critical authentication bypass vulnerability in Proxmox VE versions 7.0 to 7.4. This flaw, which allows attackers to log in as root without a password, has been actively exploited. Affected users are urged to upgrade to Proxmox VE 8.0.4 for a permanent fix. The vulnerability was reported by multiple sources, and proof-of-concept code has been made public. Administrators unable to upgrade should restrict API access to trusted networks and implement a temporary patch provided by Proxmox.
Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild
CyberSIXT Evidence Panel
Primary Source
gist.github.com
Article by CyberSIXT