Configuration Exposure in Pterodactyl's Wings Server Control Plane
CVE-2026-52855

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-52855?

Wings, the server control plane for Pterodactyl, is exposed to a configuration vulnerability that allows low-privileged users to access sensitive tokens and registry details. Specifically, prior to version 1.12.3, unsafe {{config.}} placeholders in egg configuration-file templates could inadvertently disclose values such as {{config.token}}, {{config.token_id}}, and {{config.docker.registries}}. This exposure poses a risk to the integrity and security of game servers managed through Pterodactyl, as unauthorized access to these configurations could facilitate further attacks. The issue has been resolved in version 1.12.3, where security measures have been enhanced to protect sensitive information.

Affected Version(s)

wings < 1.12.3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.