---
id: CVE-2025-68954
title: 'Pterodactyl is a free, open-source game server management panel'
summary: >-
  Pterodactyl is a free, open-source game server management panel. Versions
  1.11.11 and below do not revoke active SFTP connections when a user is removed
  from a server instance or has their permissions changes with respect to file
  access …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-613
vendor: pterodactyl
product: panel
affected:
  - panel < 1.12.0
  - wings < 1.12.0
patched:
  - panel 1.12.0
  - wings 1.12.0
published: '2026-01-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68954'
references:
  - url: >-
      https://github.com/pterodactyl/panel/commit/2bd9d8baddb0e0606e4a9d5be402f48678ac88d5
    label: security-advisories@github.com
  - url: 'https://github.com/pterodactyl/panel/releases/tag/v1.12.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/pterodactyl/panel/security/advisories/GHSA-8c39-xppg-479c
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00245
epssPercentile: 0.14249
ingestedAt: '2026-09-30T22:27:27.699Z'
---

## Overview

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.

## Affected

- `panel < 1.12.0`
- `wings < 1.12.0`

## Remediation

Upgrade past the affected range:

- `panel 1.12.0`
- `wings 1.12.0`
