<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pterodactyl Panel (&lt; 1.14.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pterodactyl-panel--1.14.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 11:32:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pterodactyl-panel--1.14.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Pterodactyl Panel Authorization Bypass in Scheduled Tasks</title><link>https://feed.craftedsignal.io/briefs/2026-09-pterodactyl-auth-bypass/</link><pubDate>Sat, 05 Sep 2026 11:32:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-pterodactyl-auth-bypass/</guid><description>Pterodactyl Panel versions prior to 1.14.1 contain an authorization bypass vulnerability allowing subusers with limited schedule update permissions to execute arbitrary console commands.</description><content:encoded><![CDATA[<p>Pterodactyl Panel before version 1.14.1 contains an authorization bypass vulnerability identified as CVE-2026-86177. The vulnerability exists within the application's permission validation logic for scheduled tasks. A subuser assigned only the 'schedule.update' permission can craft malicious scheduled task requests that include unauthorized actions, such as executing arbitrary game-server console commands, modifying server power states, or initiating backups. This flaw effectively grants unauthorized subusers elevated control over game server instances, bypassing intended role-based access controls within the panel. Defenders should prioritize patching to version 1.14.1 or later to mitigate the risk of unauthorized server management and command execution by low-privileged accounts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a subuser to execute arbitrary console commands with the privileges of the game server process, leading to potential RCE, unauthorized data access, or denial of service by manipulating power states and backups. This impact is significant for hosting environments managing multi-tenant game server infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Pterodactyl Panel instances to version 1.14.1 or later immediately.</li>
<li>Audit existing scheduled tasks within the Pterodactyl Panel to identify any unauthorized or suspicious commands initiated by subusers.</li>
<li>Review role-based access control (RBAC) configurations to ensure the 'schedule.update' permission is only assigned to trusted users until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>