๐Ÿ” CVE Alert

CVE-2026-54593

HIGH 8.1

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.

CWE CWE-1259 CWE-1270
Vendor pterodactyl
Product panel
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for pterodactyl panel

Be the first to know when new high vulnerabilities affecting pterodactyl panel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

pterodactyl / panel
< 1.12.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r github.com: https://github.com/pterodactyl/panel/pull/5636 github.com: https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7 github.com: https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c