Race Condition Vulnerability in Proxmox Virtual Environment Affecting VNC Sessions
CVE-2026-51082
7.2HIGH
What is CVE-2026-51082?
In Proxmox Virtual Environment (PVE), a race condition exists between the vncproxy and vncwebsocket API calls. This can be exploited by a user with privileges to call 'vncproxy', enabling them to hijack an active VNC session established by another user on a different virtual machine (VM). This vulnerability affects multiple versions of pve-manager, qemu-server, and pve-container, making it crucial for users to apply available security updates to mitigate potential unauthorized access to VNC sessions.
