ZeroHour

CVE-2026-86177

moderate

Missing Authorization in Pterodactyl Panel Lets Subusers Run Arbitrary Commands

CVSS 4.0
8.7 high
EPSS
<1%p23
Published
()
Modified
AI analysis

Pterodactyl Panel before 1.14.1 does not validate action-specific permissions when scheduled tasks are created (CWE-862), a broken-access-control flaw. A subuser granted only the schedule.update permission can create a scheduled task and immediately trigger it, bypassing the intended permission checks. Through such tasks the attacker can run arbitrary game-server console commands, change server power state, or create backups, giving them high confidentiality, integrity, and availability impact on the affected server despite holding minimal privileges. Anyone running Pterodactyl Panel prior to 1.14.1 who has granted subusers schedule access is affected. There are no reports of exploitation in the wild, no public proof-of-concept, and a low (0.3%) EPSS probability of exploitation in the next 30 days.

What to do: Upgrade Pterodactyl Panel to version 1.14.1 or later. Until patched, review subuser permission grants for schedule.update, audit existing scheduled tasks for unauthorized entries (especially tasks running console commands, power actions, or backups), and check task logs for unexpected activity. Restrict schedule-related subuser permissions to trusted accounts where immediate patching is not possible.

Affected
Pterodactyl Panelbefore 1.14.1
Estimated exposure
moderatetens of thousands of users across thousands of deployed panels (estimate, not a measured figure) — Public internet scans regularly surface thousands of exposed Pterodactyl Panel instances, and its widespread adoption by game-server hosting providers implies additional private deployments and many subuser accounts, placing realistic…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.