Panel

Pterodactyl · 16 CVEs

CVE-2026-86177
HIGH

Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks

Sep 5, 2026

CVE-2026-61609
HIGH

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authenticatio…

Jul 28, 2026

CVE-2026-54593
HIGH

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

Jul 28, 2026

CVE-2026-35202
LOW

Pterodactyl has a database resource limit bypass via race condition in Client API

Jun 2, 2026

CVE-2026-26016
CRITICAL

Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

Feb 19, 2026

CVE-2025-69199
HIGH

Pterodactyl Wings's websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks under certa…

Jan 19, 2026

CVE-2025-69198
MEDIUM

Pterodactyl's improper resource locking allows raced queries to create more resources than alloted

Jan 19, 2026

CVE-2025-69197
MEDIUM

Pterodactyl TOTPs can be reused during validity window

Jan 6, 2026

CVE-2025-68954
HIGH

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

Jan 6, 2026

CVE-2025-49132
CRITICAL

Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

Jun 20, 2025

CVE-2024-49762
MEDIUM

Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled

Oct 24, 2024

CVE-2024-34067
MEDIUM

Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel

May 3, 2024

CVE-2021-41273
MEDIUM

Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys

Nov 17, 2021

CVE-2021-41176
MEDIUM

logout CSRF in Pterodactyl Panel

Oct 25, 2021

CVE-2021-41129
HIGH

Authentication bypass in Pterodactyl

Oct 6, 2021

CVE-2019-1020002
HIGH

Pterodactyl before 0.7.14 with 2FA allows credential sniffing.

Jul 29, 2019

Showing 1 to 16 of 16 CVEs