{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pterodactyl-panel--1.14.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pterodactyl:panel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-86177"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pterodactyl Panel (\u003c 1.14.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Pterodactyl"],"content_html":"\u003cp\u003ePterodactyl Panel before version 1.14.1 contains an authorization bypass vulnerability identified as CVE-2026-86177. The vulnerability exists within the application's permission validation logic for scheduled tasks. A subuser assigned only the 'schedule.update' permission can craft malicious scheduled task requests that include unauthorized actions, such as executing arbitrary game-server console commands, modifying server power states, or initiating backups. This flaw effectively grants unauthorized subusers elevated control over game server instances, bypassing intended role-based access controls within the panel. Defenders should prioritize patching to version 1.14.1 or later to mitigate the risk of unauthorized server management and command execution by low-privileged accounts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a subuser to execute arbitrary console commands with the privileges of the game server process, leading to potential RCE, unauthorized data access, or denial of service by manipulating power states and backups. This impact is significant for hosting environments managing multi-tenant game server infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Pterodactyl Panel instances to version 1.14.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit existing scheduled tasks within the Pterodactyl Panel to identify any unauthorized or suspicious commands initiated by subusers.\u003c/li\u003e\n\u003cli\u003eReview role-based access control (RBAC) configurations to ensure the 'schedule.update' permission is only assigned to trusted users until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T11:32:07Z","date_published":"2026-09-05T11:32:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pterodactyl-auth-bypass/","summary":"Pterodactyl Panel versions prior to 1.14.1 contain an authorization bypass vulnerability allowing subusers with limited schedule update permissions to execute arbitrary console commands.","title":"Pterodactyl Panel Authorization Bypass in Scheduled Tasks","url":"https://feed.craftedsignal.io/briefs/2026-09-pterodactyl-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Pterodactyl Panel (\u003c 1.14.1)","version":"https://jsonfeed.org/version/1.1"}