{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wings--1.12.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-52855"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wings (\u003c 1.12.3)"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","authentication-bypass","pterodactyl","wings"],"_cs_type":"advisory","_cs_vendors":["Pterodactyl"],"content_html":"\u003cp\u003ePterodactyl Wings versions prior to 1.12.3 contain a critical security vulnerability (CVE-2026-52855) where the daemon configuration is exposed to the egg configuration-file templating engine. Attackers with low-privileged access - such as server owners or subusers with \u003ccode\u003estartup.update\u003c/code\u003e permissions - can inject \u003ccode\u003e{{config.*}}\u003c/code\u003e placeholders into user-editable egg variables. When Wings renders these variables into server configuration files, it resolves the placeholders against the full daemon configuration, effectively disclosing sensitive credentials.\u003c/p\u003e\n\u003cp\u003eImpacted data includes the node's daemon token (used for Panel-to-Wings communication and JWT signing) and container registry credentials. Disclosure of the daemon token grants an attacker the ability to forge authentication tokens and execute commands across all servers hosted on the compromised node, leading to a complete node takeover. This vulnerability is prevalent in multi-tenant environments using stock or community-provided eggs that allow the rendering of user-controlled variables into configuration files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Pterodactyl Panel using a low-privileged account (e.g., server owner or subuser with \u003ccode\u003estartup.update\u003c/code\u003e rights).\u003c/li\u003e\n\u003cli\u003eAttacker identifies an egg configuration in use that renders a user-editable variable into a server configuration file via \u003ccode\u003e{{server.build.env.*}}\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the specific user-editable variable in the Panel, injecting a \u003ccode\u003e{{config.token}}\u003c/code\u003e or \u003ccode\u003e{{config.docker.registries}}\u003c/code\u003e placeholder.\u003c/li\u003e\n\u003cli\u003eThe Panel accepts the malicious input and transmits the egg configuration containing the placeholder to the Wings daemon.\u003c/li\u003e\n\u003cli\u003eWings processes the template and resolves the \u003ccode\u003e{{config.token}}\u003c/code\u003e placeholder against the internal daemon configuration.\u003c/li\u003e\n\u003cli\u003eWings writes the resolved, sensitive credential into the target configuration file located within the server's directory.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the server file via the built-in File Manager or SFTP to read the exfiltrated sensitive data.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the stolen daemon token to forge authentication tokens, achieving full node compromise and administrative control over all hosted server instances.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in the full exposure of node-level credentials, including the daemon token and registry secrets. Successful exploitation allows a low-privileged attacker to achieve full node compromise. This affects any multi-tenant environment using Pterodactyl, where unauthorized parties can read data belonging to other users or the host system itself. Admins must upgrade Wings to v1.12.3 and rotate all node tokens to remediate the exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Pterodactyl Wings to version 1.12.3 or later immediately to restrict the configuration data accessible to the templating engine.\u003c/li\u003e\n\u003cli\u003eAfter upgrading, rotate all affected node daemon tokens via the Admin interface (Nodes \u0026gt; Configuration \u0026gt; Reset Token) and trigger a re-deployment of the \u003ccode\u003econfig.yml\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eAudit all active eggs for user-editable variables that are rendered into configuration files; set these variables to non-editable if they are not strictly required by the server owner.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unusual changes to startup parameters or environment variables in Pterodactyl logs, specifically looking for placeholders like \u003ccode\u003e{{config.\u003c/code\u003e as an indicator of attempted exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:20:31Z","date_published":"2026-07-31T19:20:31Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wings-secret-exposure/","summary":"The Pterodactyl Wings daemon improperly exposes its full configuration to the egg templating engine, allowing low-privileged users to exfiltrate sensitive node secrets, including daemon tokens and registry credentials, via crafted configuration placeholders.","title":"Pterodactyl Wings Configuration Secret Exposure via Egg Templating","url":"https://feed.craftedsignal.io/briefs/2026-07-wings-secret-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - Wings (\u003c 1.12.3)","version":"https://jsonfeed.org/version/1.1"}