{"id":"CVE-2025-68954","title":"Pterodactyl is a free, open-source game server management panel","summary":"Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-613"],"vendor":"pterodactyl","product":"panel","affected":["panel < 1.12.0","wings < 1.12.0"],"patched":["panel 1.12.0","wings 1.12.0"],"published":"2026-01-06","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68954","references":[{"url":"https://github.com/pterodactyl/panel/commit/2bd9d8baddb0e0606e4a9d5be402f48678ac88d5","label":"security-advisories@github.com"},{"url":"https://github.com/pterodactyl/panel/releases/tag/v1.12.0","label":"security-advisories@github.com"},{"url":"https://github.com/pterodactyl/panel/security/advisories/GHSA-8c39-xppg-479c","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00245,"epssPercentile":0.14249,"ingestedAt":"2026-09-30T22:27:27.699Z","slug":"CVE-2025-68954","body":"## Overview\n\nPterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.\n\n## Affected\n\n- `panel < 1.12.0`\n- `wings < 1.12.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `panel 1.12.0`\n- `wings 1.12.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}