Updates & News
Proxmox VE 7: Attackers Log In as Root Without a Password
A parameter in the two-factor login flow made the password check fail entirely: in Proxmox VE 7, attackers could log in as root without any credentials. The flaw was fixed by accident in July 2023, but the fix was never backported to VE 7 — and it has been actively exploited since late August. Prepaid-Host is not affected.