SFTP Write Abuse Vulnerability in Wings Server Control Plane by Pterodactyl
CVE-2026-61617

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-61617?

The Wings server control plane for Pterodactyl allows users with SFTP write access to bypass disk quota limitations. This occurs because the SFTP write path does not enforce the server's disk quota during data transfers. When a user initiates a file upload, Wings checks available disk space only once using outdated cache data and does not account for the size of incoming files, resulting in potential unlimited disk usage. This flaw can lead to total disk exhaustion, taking down all servers hosted on the node. The issue has been formally addressed in version 1.13.3.

Affected Version(s)

wings < 1.13.3

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.