pterodactyl/panel vulnerabilities
CVEs whose affected-version data names the pterodactyl/panel package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-54593High· 8.1Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.36%via GHSA
CVE-2026-61609High· 7.5Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.39%via GHSA
GHSA-j7f5-gfqm-pcx3MediumPterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
▾ Sunlitpterodactyl · pterodactyl/panelvia GHSA