top of page
perceptive_background_267k.jpg

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configurat…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 18:01:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Enterprise Applications

CVE-2026-52855 affects Wings, the server control plane for Pterodactyl, an open-source game server management panel. Prior to version 1.12.3, template placeholders in egg configuration-file templates ({{config.}}) could be exploited by low-privileged users to read sensitive daemon configuration values including config.token, config.token_id, and config.docker.registries. This represents an unauthorized information disclosure vulnerability that could expose authentication tokens and Docker registry credentials. The flaw exists in how the template engine processes configuration placeholders without proper access controls. A patch has been issued in version 1.12.3 of Wings. Users are strongly advised to upgrade immediately to prevent credential exposure. The fix is documented in the official GitHub commit and security advisory.

Technical details

Mitigation steps:

Affected products:

Pterodactyl Wings
Pterodactyl

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page