
CVE-2026-52855 (CVSS 9.9): Pterodactyl Wings leaks its entire daemon config through egg templates. Any {{config.path}} placeholder resolves against the full marshalled config: API keys, SFTP creds, DB strings. No restriction on which paths can be read. Fixed in Wings 1.12.3. https://hol.org/blog/cve-2026-52855-pterodactyl-wings-configuration-secrets-leak
Post summary
The note announces CVE-2026-52855, which leaks the full Pterodactyl Wings daemon configuration through egg templates, and indicates the issue was fixed in Wings 1.12.3.



