CVE-2026-86177
moderateMissing Authorization in Pterodactyl Panel Lets Subusers Run Arbitrary Commands
Pterodactyl Panel before 1.14.1 does not validate action-specific permissions when scheduled tasks are created (CWE-862), a broken-access-control flaw. A subuser granted only the schedule.update permission can create a scheduled task and immediately trigger it, bypassing the intended permission checks. Through such tasks the attacker can run arbitrary game-server console commands, change server power state, or create backups, giving them high confidentiality, integrity, and availability impact on the affected server despite holding minimal privileges. Anyone running Pterodactyl Panel prior to 1.14.1 who has granted subusers schedule access is affected. There are no reports of exploitation in the wild, no public proof-of-concept, and a low (0.3%) EPSS probability of exploitation in the next 30 days.
What to do: Upgrade Pterodactyl Panel to version 1.14.1 or later. Until patched, review subuser permission grants for schedule.update, audit existing scheduled tasks for unauthorized entries (especially tasks running console commands, power actions, or backups), and check task logs for unexpected activity. Restrict schedule-related subuser permissions to trusted accounts where immediate patching is not possible.
| Pterodactyl Panel | before 1.14.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.