


Perceptive Security
SOC/SIEM Consultancy

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepte…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 17:04:58
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-54593 affects Pterodactyl, a free open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint failed to validate the intended purpose of panel-signed JWTs. Because JWTs issued for lower-privilege operations (e.g., WebSocket authentication, file-download links) contained the same claims (server_uuid, user_uuid, unique_id) as higher-privilege tokens, an authenticated subuser could replay a lower-privilege token against the /upload/file endpoint. This allowed arbitrary file writes to a server without possessing the file.create permission, constituting a privilege escalation and authorization bypass vulnerability. The flaw is classified as a JWT token reuse/confused deputy attack. Fixes have been released in Panel version 1.12.3 and Wings version 1.12.2. Users are advised to update immediately to mitigate unauthorized file write risks.
Technical details
Mitigation steps:
Affected products:
Pterodactyl Panel
Pterodactyl Wings
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54593
https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7
https://github.com/pterodactyl/panel/pull/5636
https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r
https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
