Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-51080 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-51080 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-51080 is an XML External Entity (XXE) vulnerability in libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7, Perl storage-library components used in Proxmox VE environments.

Technical Detail

The flaw occurs when affected components parse XML in a manner that permits resolution of external entities. An attacker would need to cause the vulnerable code to process attacker-controlled XML containing a crafted entity declaration; the specific exposed XML ingestion path has not been publicly confirmed. Depending on parser configuration and application privileges, successful exploitation may allow disclosure of locally accessible files, server-side request forgery to internal services, or interaction with external resources.

Exploitation Status

No known exploit has been reported as of July 24, 2026. CVE-2026-51080 is not listed in CISA's Known Exploited Vulnerabilities catalog.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Treat this as a high-priority patching issue due to its Critical CVSS score. Obtain and deploy the vendor-provided fixed package version when available, and verify whether libpvestorage-perl v9.1.1 or libpve-storage-perl v8.3.7 is installed on Proxmox VE systems. Until updated, prevent untrusted users and services from supplying XML to affected workflows, disable DTD and external-entity processing where configuration permits, and restrict outbound network access from affected hosts to limit external entity retrieval and internal-service access. Monitor application and XML-parser logs for unexpected DOCTYPE or ENTITY declarations, parser errors involving external resources, and unusual outbound connections originating from Proxmox VE hosts.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →