Product
Pterodactyl Panel versions prior to 1.14.1 contain an authorization bypass vulnerability allowing subusers with limited schedule update permissions to execute arbitrary console commands.