


Perceptive Security
SOC/SIEM Consultancy

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configurat…
Published:
30 juli 2026 om 22:00:00
Alert date:
31 juli 2026 om 18:01:57
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Enterprise Applications
CVE-2026-52855 affects Wings, the server control plane for Pterodactyl, an open-source game server management panel. Prior to version 1.12.3, template placeholders in egg configuration-file templates ({{config.}}) could be exploited by low-privileged users to read sensitive daemon configuration values including config.token, config.token_id, and config.docker.registries. This represents an unauthorized information disclosure vulnerability that could expose authentication tokens and Docker registry credentials. The flaw exists in how the template engine processes configuration placeholders without proper access controls. A patch has been issued in version 1.12.3 of Wings. Users are strongly advised to upgrade immediately to prevent credential exposure. The fix is documented in the official GitHub commit and security advisory.
Technical details
Mitigation steps:
Affected products:
Pterodactyl Wings
Pterodactyl
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-52855
https://github.com/pterodactyl/wings/commit/eb65e27ae077a63e38518c490768486af1cd86a9
https://github.com/pterodactyl/wings/releases/tag/v1.12.3
https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
