Argument Injection Vulnerability in Proxmox pmg-api Affecting Proxmox Mail Gateway
CVE-2026-94588

4.4MEDIUM

Key Information:

Vendor

Proxmox

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94588?

In Proxmox Mail Gateway's pmg-api component, an argument injection vulnerability exists in the changelog retrieval feature. This issue arises from the improper handling of user-supplied input when executing the underlying apt-get command. While it requires user authentication, the vulnerability can be exploited through CSRF-style attacks, potentially allowing unauthorized access to sensitive package changelogs.

Affected Version(s)

pmg-api 9.0.0 < 9.0.3

pmg-api 0 < 8.2.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.