← all CVEs

CVE-2026-94588

Published 21 Sep 2026Updated 21 Sep 2026

Severity: MEDIUM

4.4

CVSS Base Score

Description

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package changelogs. It requires authentication but can be exploited in a CSRF-style attack.

Affected products (1)

  • Proxmox pmg-api

Problem types

  • CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Get alerted the moment a CVE like this matches your stack.

Create a free account