SQL Logic Error in Pterodactyl's Wings Panel Allows Data Flooding
CVE-2026-21696
What is CVE-2026-21696?
Wings, the server control plane for Pterodactyl, is affected by a vulnerability that allows low-privileged users to exploit the system's handling of activity log entries. Versions between 1.7.0 and 1.11.0 fail to adhere to SQLite's max parameter limit, which can lead to repetitive activity data resubmissions to the panel. An attacker can trigger this exploit, causing the database to repeatedly process entries until resources are exhausted, specifically when Wings attempts to delete excessive entries. This condition creates a scenario where the server may run out of disk space due to ongoing data overload. An update to version 1.12.0 resolves this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wings >= 1.7.0, < 1.12.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
