PT-2026-86401 · Unknown · Pterodactyl Panel

·

CVE-2026-86177

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pterodactyl Panel versions prior to 1.14.1
Description The software fails to validate action-specific permissions during the creation of scheduled tasks. This allows subusers who possess only the schedule.update permission to execute arbitrary console commands. An attacker can create and immediately trigger scheduled tasks to run game-server console commands, control the server power state, or create backups without the required authorization checks.
Recommendations Update Pterodactyl Panel to version 1.14.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86177

Affected Products

Pterodactyl Panel