CVE-2026-26016Patch(pterodactyl / panel)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch pterodactyl panel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, even if that server is associated with a different node. This issue stems from missing logic to verify that the node requesting server data is the same node that the server is associated with. Any authenticated Wings node can retrieve server installation scripts (potentially containing secret values) and manipulate the installation status of servers belonging to other nodes. Wings nodes may also manipulate the transfer status of servers belonging to other nodes. This vulnerability requires a user to acquire a secret access token for a node. Unless a user gains access to a Wings secret access token they would not be able to access any of these vulnerable endpoints, as every endpoint requires a valid node access token. A single compromised Wings node daemon token (stored in plaintext at `/etc/pterodactyl/config.yml`) grants access to sensitive configuration data of every server on the panel, rather than only to servers that the node has access to. An attacker can use this information to move laterally through the system, send excessive notifications, destroy server data on other nodes, and otherwise exfiltrate secrets that they should not have access to with only a node token. Additionally, triggering a false transfer success causes the panel to delete the server from the source node, resulting in permanent data loss. Users should upgrade to version 1.12.1 to receive a fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-283CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • panel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-02-19)
  • 3 total mentions across 2 days

Affected systems

Products
panel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-18: 1Mentions · 2026-02-19: 2Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 2Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 202-1802-19
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-181
Patch1
2026-02-192
Patch2
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical Pterodactyl API flaw (CVE-2026-26016) allows cross-node authorization bypass. Attackers can destroy game servers. Update to version 1.12.1 now. #Pterodactyl #CyberSecurity #CVE202626016 #GameServer #API #InfoSec #PatchAlert https://securityonline.info/cve-2026-26016-critical-pterodactyl-api-flaw-cvss-9-2-exposes-entire-server-networks/

    Post summary

    A critical Pterodactyl API flaw (CVE‑2026‑26016) allows cross‑node authorization bypass and can let attackers destroy game servers; the issue is mitigated by updating to version 1.12.1.

    00030375
    10.3K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Pterodactyl Panel <1.12.1 vuln lets attackers with a Wings node token access & destroy any server! Upgrade now to stay secure. 🔒 https://radar.offseq.com/threat/cve-2026-26016-cwe-639-authorization-bypass-throug-e8901bb1 #OffSeq #Pterodactyl #Vulnerability https://t.co/KfwH8hHYep

    Post summary

    The tweet highlights a critical authorization bypass in Pterodactyl Panel versions below 1.12.1 via its Wings node token and urges users to upgrade to mitigate the risk.

    0000036
    265 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A missing authorization vulnerability (CVE-2026-26016) in `Pterodactyl Panel` could expose cross-node server configurations via its remote API. Patching to version 1.12.1 or later is recommended to mitigate this #Pterodactyl #Infosec #CVE. https://www.pulsepatch.io/posts/cve-2026-26016-pterodactyl-panel-config-disclosure

    Post summary

    The post highlights a missing authorization flaw in Pterodactyl Panel that could expose cross‑node configurations and recommends upgrading to version 1.12.1 or later for mitigation.

    0000029
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppterodactylpanel---

Explore more