Configuration Exposure in Pterodactyl's Wings Server Control Plane
CVE-2026-52855
9.9CRITICAL
What is CVE-2026-52855?
Wings, the server control plane for Pterodactyl, is exposed to a configuration vulnerability that allows low-privileged users to access sensitive tokens and registry details. Specifically, prior to version 1.12.3, unsafe {{config.}} placeholders in egg configuration-file templates could inadvertently disclose values such as {{config.token}}, {{config.token_id}}, and {{config.docker.registries}}. This exposure poses a risk to the integrity and security of game servers managed through Pterodactyl, as unauthorized access to these configurations could facilitate further attacks. The issue has been resolved in version 1.12.3, where security measures have been enhanced to protect sensitive information.
Affected Version(s)
wings < 1.12.3
