Pterodactyl
Pterodactyl Panel: vulnerabilidades y CVE
Pterodactyl Panel tiene 12 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86177 | Alta (8.7) | 0.58% | — | 5 sept 2026 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can… |
| CVE-2026-54593 | Alta (8.1) | 0.68% | — | 28 jul 2026 | Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid,… |
| CVE-2026-26016 | Crítica (9.2) | 0.46% | — | 19 feb 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node… |
| CVE-2025-69198 | Media (6) | 0.24% | — | 19 ene 2026 | Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an… |
| CVE-2025-69197 | Media (6.5) | 0.36% | — | 6 ene 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during… |
| CVE-2025-68954 | Alta (7.5) | 0.24% | — | 6 ene 2026 | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with… |
| CVE-2024-49762 | Media (4.6) | 0.14% | — | 24 oct 2024 | Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While… |
| CVE-2024-34067 | Media (6.1) | 0.46% | — | 3 may 2024 | Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which… |
| CVE-2021-41273 | Media (4.3) | 0.39% | — | 17 nov 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the… |
| CVE-2021-41176 | Media (4.3) | 0.52% | — | 25 oct 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website… |
| CVE-2021-41129 | Alta (8.1) | 1.8% | — | 6 oct 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to… |
| CVE-2019-1020002 | Alta (7.5) | 1.5% | — | 29 jul 2019 | Pterodactyl before 0.7.14 with 2FA allows credential sniffing. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.