Description
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.
Published: 2026-07-17
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition (CWE-362) between the vncproxy and vncwebsocket API calls allows an attacker with privileged access to invoke vncproxy and hijack a VNC session that a different authenticated user has established for another virtual machine. Successful hijacking grants the attacker visibility into, and control over, the victim’s VM, thereby compromising confidentiality and integrity of virtual machine data and potentially the host system.

Affected Systems

Proxmox Virtual Environment 9.x and 8.x are affected. The pve-manager component is vulnerable when older than v9.1.9 for 9.x or older than v8.4.19 for 8.x. The qemu-server component is impacted if older than v9.1.7 for 9.x or older than v8.4.7 for 8.x. The pve-container component is vulnerable when older than v6.1.3 for 9.x or older than v5.3.4 for 8.x.

Risk and Exploitability

The identified flaw has a CVSS score of 7.2, indicating high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation under current conditions. It is not listed in the CISA KEV catalog. Attackers would typically need authenticated access to the Proxmox management interface, either locally or over the network, to call the vncproxy API. If the vulnerability is exploited, the attacker obtains full control over the target VM via the hijacked VNC session.

Generated by OpenCVE AI on July 31, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade pve-manager to v9.1.9 or later for PVE 9.x, or to v8.4.19 or later for PVE 8.x.
  • Upgrade qemu-server to v9.1.7 or later for PVE 9.x, or to v8.4.7 or later for PVE 8.x.
  • Upgrade pve-container to v6.1.3 or later for PVE 9.x, or to v5.3.4 or later for PVE 8.x.
  • If patching is not immediately possible, restrict VNC access only to trusted users and isolate VNC traffic using firewall rules or ACLs.

Generated by OpenCVE AI on July 31, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Race Condition Enables VNC Session Hijacking in Proxmox Virtual Environment

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Proxmox
Proxmox pve-container
Proxmox pve-manager
Qemu
Qemu qemu
Vendors & Products Proxmox
Proxmox pve-container
Proxmox pve-manager
Qemu
Qemu qemu

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allows VNC Session Hijacking in Proxmox Virtual Environment

Wed, 22 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allows VNC Session Hijacking in Proxmox Virtual Environment

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager 9.1.x before 9.1.9 and 8.4.x before 8.4.19; qemu-server 9.1.x before 9.1.7 and 8.4.x before 8.4.7; and pve-container 6.1.x before 6.1.3 and 5.3.x before 5.3.4 allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM. A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.

Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager 9.1.x before 9.1.9 and 8.4.x before 8.4.19; qemu-server 9.1.x before 9.1.7 and 8.4.x before 8.4.7; and pve-container 6.1.x before 6.1.3 and 5.3.x before 5.3.4 allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.
References

Subscriptions

Proxmox Pve-container Pve-manager
Qemu Qemu
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T16:44:44.740Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51082

cve-icon Vulnrichment

Updated: 2026-07-17T16:44:40.348Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')