CVE-2026-94588
Received Received - Intake

Argument Injection in Proxmox PMG-API via APT Changelog

Vulnerability report for CVE-2026-94588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
proxmox pmg-api *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an argument injection flaw in Proxmox pmg-api's package changelog retrieval feature. It occurs when user input is improperly handled and passed to the apt-get command, allowing attackers to inject malicious arguments. Exploitation requires authentication but can be done via a CSRF-style attack.

Impact Analysis

An attacker could exploit this to execute unauthorized commands on the system with limited privileges. This may lead to data leakage, unauthorized modifications, or further compromise of the Proxmox environment. The impact is moderate due to the need for authentication and limited command execution.

Compliance Impact

This vulnerability could potentially violate compliance requirements by allowing unauthorized access or data exfiltration. GDPR may be impacted if personal data is exposed, while HIPAA could be affected if protected health information is compromised. Organizations must assess their specific environment.

Mitigation Strategies

Update Proxmox PMG to the latest patched version immediately to address the argument injection flaw in package changelog retrieval.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart