PT-2026-6295 · Hashicorp+2 · Terraform+2
Lucasmaurice
·
Published
2026-02-02
·
Updated
2026-02-06
·
CVE-2026-25499
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Terraform / OpenTofu Provider versions prior to 0.93.1
Description
The Terraform / OpenTofu Provider for Proxmox Virtual Environment, prior to version 0.93.1, contains an insecure sudoer line in its SSH configuration documentation. This configuration allows for potential path traversal using '../', enabling modification of any file on the system.
Recommendations
Update to version 0.93.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentofu
Proxmox Virtual Environment
Terraform