Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.
References
Configurations
No configuration.
History
17 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
17 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 15:16
Updated : 2026-07-17 18:29
NVD link : CVE-2026-51083
Mitre link : CVE-2026-51083
CVE.ORG link : CVE-2026-51083
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
