pterodactyl/panel Security Advisories for v1.12.1 (4)
-
[HIGH] Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
PKSA-hhbv-vvdq-cchz CVE-2026-54593 GHSA-8r6w-3qq5-4p4r
Affected version: <1.12.3
Reported by:
GitHub -
[HIGH] Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
PKSA-dkjc-6qnp-q5rq CVE-2026-61609 GHSA-xvc3-826v-xf47
Affected version: >=1.7.0,<=1.12.4
Reported by:
GitHub -
[MEDIUM] Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
PKSA-mzmz-41cv-9dtv GHSA-j7f5-gfqm-pcx3
Affected version: <1.12.3
Reported by:
GitHub -
[LOW] Pterodactyl has a database resource limit bypass via race condition in Client API
PKSA-d16c-6bkx-pfvs CVE-2026-35202 GHSA-fgmm-w5cx-vrfw
Affected version: <1.12.3
Reported by:
GitHub