Proxmox Server Solutions GmbH Proxmox Virtual Environment (VE) processes API login through POST /api2/json/access/ticket, where tfa-challenge is used to complete TFA. In affected versions, this value was not validated for users without a configured second factor, while the presence of the parameter also caused password verification to be skipped entirely. An attacker could therefore authenticate as any existing enabled user without a second factor by supplying an arbitrary tfa-challenge value, without knowing valid credentials. Exploitation requires reachability to the API, directly or through a reverse proxy, on port 8006. This is CWE-304, Missing Critical Step in Authentication; the available evidence does not establish that every deployment exposes this API to the Internet.