PatchSiren

pterodactyl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Pterodactyl CVE published 2026-09-05

CVE-2026-86177

Pterodactyl Panel before 1.14.1 has a vulnerability allowing subusers with schedule.update permission to execute arbitrary console commands by creating and triggering scheduled tasks without proper authorization checks. This high-severity issue enables attackers to control server power state, create backups, or run game-server console commands. Defenders should assess exposure, apply the vendor-provided p [truncated]

HIGH pterodactyl CVE published 2026-08-26

CVE-2026-61617

CVE-2026-61617 debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T22:16:25.247Z and has not been modified since then. This vulnerability affects Pterodactyl's Wings server control plane, allowing tenants with SFTP write access to exhaust the host node's physical disk, impacting all servers. The issue is fixed in version 1.13.3, and defenders should assess exposure and [truncated]

HIGH pterodactyl CVE published 2026-07-31

CVE-2026-52856

A malformed packet received during the SFTP connection handshake causes a Go panic in Wings, the server control plane for Pterodactyl, a free, open-source game server management panel, prior to version 1.13.0. The issue is fixed in version 1.13.0. This vulnerability affects administrators of Pterodactyl game servers, users of Wings, and security teams responsible for vulnerability management. They should [truncated]

CRITICAL pterodactyl CVE published 2026-07-31

CVE-2026-52855

CVE-2026-52855 is a critical vulnerability in Wings, the server control plane for Pterodactyl. A low-privileged user can exploit this vulnerability to read sensitive configuration data. The issue is fixed in version 1.12.3. Users should be aware of this vulnerability and take steps to upgrade. This vulnerability has a CVSS score of 9.9 and is considered CRITICAL. The CVE record was published on 2026-07-31 [truncated]