Token Misuse Vulnerability in Pterodactyl Game Server Management Panel
CVE-2026-54593

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-54593?

The Pterodactyl game server management panel has a vulnerability that allows authenticated subusers to misuse valid panel-issued JSON Web Tokens (JWTs) for unauthorized file uploads. The issue arises from the /upload/file endpoint, which accepts any valid JWT containing necessary claims without adequately validating the token's intended purpose. This flaw permits the reuse of lower-privilege tokens, such as those meant for WebSocket connections or file downloads, thus allowing users to write arbitrary files to the server without having the right permissions. This vulnerability is addressed in the recent updates to both the Pterodactyl Panel and Wings.

Affected Version(s)

panel < 1.12.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.