CVE-2023-54391 affects Proxmox Virtual Environment 7.0 through 8.0 where libpve-access-control is older than 8.0.4. An unauthenticated remote attacker can send an arbitrary tfa-challenge value to the API login endpoint and bypass password verification, authenticating as an enabled account that has no second factor configured, potentially including root@pam.
The flaw is rated critical in impact (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and places exposed management interfaces on TCP port 8006 at risk of full administrative compromise and remote code execution through the platform. Reports alleged active compromises of Internet-exposed, end-of-life Proxmox VE 7 systems; organizations should urgently remove management interfaces from public exposure, upgrade to a fixed supported release, and investigate affected hosts for unauthorized access.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
A contributor submitted a Nuclei YAML template for an alleged Proxmox VE default-credentials issue with TFA bypass, including an HTTP request and matchers intended to identify the condition. The pull request was marked Done and Ready to merge, but did not provide a CVE, affected versions, vendor validation, or exploitation evidence.
A Reddit post alleged that end-of-life Proxmox VE releases from 7.0-7 through before 8.0.4 were being exploited through exposed TCP port 8006 and that numerous systems had been rooted that day. The supplied material provides no independent confirmation of the alleged compromises or their connection to SCTPhantom.
The CVE record was updated with details of an authentication bypass in Proxmox VE 7.0 through 8.0, affecting libpve-access-control versions before 8.0.4. An unauthenticated attacker could supply an arbitrary tfa-challenge value to bypass password verification and authenticate as an enabled user without a configured second factor, potentially including root@pam.
Proxmox advisory PSA-2026-00037-1 described SCTPhantom as a use-after-free vulnerability in proxmox-kernel packages that could enable local privilege escalation. The advisory does not establish that this issue was the alleged network-accessible authentication bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
btcirt.bt
Open sourcegithub.com
Open sourcecvefeed.io
Open sourcereddit.com
Open sourceforum.proxmox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.