pterodactyl has 10 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/pterodactyl/wings (5), pterodactyl/panel (3), panel (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Weakness classes
Products
- github.com/pterodactyl/wings 5
- pterodactyl/panel 3
- panel 1
- wings 1
Worst active — by depth score
CVE-2024-27102Critical· 9.9Wings is the server control plane for Pterodactyl Panel67CVE-2026-86177High· 8.8Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands60CVE-2026-52855Critical· 9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel55CVE-2026-54593High· 8.1Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions45CVE-2026-52856High· 7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel41
pterodactyl vulnerabilities
CVEs affecting pterodactyl, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-86177High· 8.8PoCPterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately …
CVE-2026-52857Medium· 5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configur…
CVE-2026-52855Critical· 9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…
CVE-2026-52856High· 7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
CVE-2026-54593High· 8.1Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
CVE-2026-61609High· 7.5Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
GHSA-rhq6-9rgh-v45cMedium· 5.0Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
GHSA-j7f5-gfqm-pcx3MediumPterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
CVE-2024-27102Critical· 9.9PoCWings is the server control plane for Pterodactyl Panel
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full sco…
CVE-2021-32699Medium· 6.5Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings