Proxmox VE authentication bypass: port 8006 count not the key number
An authentication bypass was found in Proxmox VE 7.x–8.0.3: with the tfa-challenge parameter, code skipped password verification for accounts without 2FA, including root@pam. The vendor confirmed attacks with data encryption for extortion; PVE 7 will not receive a patch as the branch is end-of-life.
- Vulnerability PSA-2026-00043-1 affects PVE 7.x–8.0.3
- Attacker gains root access without password if no 2FA
- PVE 7 not patched — branch end-of-life before discovery
- Exploit method published, likely accelerating attacks
Read next
Security