CVE-2023-43320: Proxmox Backup Server

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.

Affected products

  • Proxmox Backup Server: from 1.1, up to and including 3.0
  • Proxmox Proxmox Mail Gateway: from 7.1, up to and including 8.0
  • Proxmox Virtual Environment: from 5.4, up to and including 8.0

Published 2023-09-27. Last modified 2026-06-17.