top of page
perceptive_background_267k.jpg

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepte…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 17:04:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-54593 affects Pterodactyl, a free open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint failed to validate the intended purpose of panel-signed JWTs. Because JWTs issued for lower-privilege operations (e.g., WebSocket authentication, file-download links) contained the same claims (server_uuid, user_uuid, unique_id) as higher-privilege tokens, an authenticated subuser could replay a lower-privilege token against the /upload/file endpoint. This allowed arbitrary file writes to a server without possessing the file.create permission, constituting a privilege escalation and authorization bypass vulnerability. The flaw is classified as a JWT token reuse/confused deputy attack. Fixes have been released in Panel version 1.12.3 and Wings version 1.12.2. Users are advised to update immediately to mitigate unauthorized file write risks.

Technical details

Mitigation steps:

Affected products:

Pterodactyl Panel
Pterodactyl Wings

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page