Management plane

Proxmox is driven by a REST API on 8006, exposed through the web UI, the pvesh CLI, and API tokens. Authentication uses realms (root@pam is the superuser) and issues tickets, or long-lived API tokens. The API controls every VM, container, and storage target, and because nodes form a cluster, API or node access to one spreads to the others.

bash
# Ticket auth, then drive the API
curl -sk -d 'username=root@pam&password=<pw>' https://<node>:8006/api2/json/access/ticket
pvesh get /cluster/resources --type vm        # all VMs across the cluster
pvesh create /nodes/<node>/qemu/<vmid>/agent/exec -command 'id'   # run in a guest (qemu-guest-agent required; returns a pid to poll)

Exploitation notes#

  • root@pam or a privileged API token is cluster-wide control; tokens are found in /etc/pve, in automation, and in backups.
  • The guest agent exec endpoint runs commands inside guests from the API, a management-plane path into VMs without an escape.
  • Cluster membership means compromising one node's /etc/pve or corosync trust reaches the whole cluster.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more