HIGH🇵🇱 Wersja polska

CVE-2025-68954

CVSS 7.5v4.0pub. 2026-01-06upd. 2026-01-12

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Pterodactyl Panel

    APP
    Pterodactyl
    < 1.12.0
  • Pterodactyl Wings

    APP
    Pterodactyl
    < 1.12.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-26016CRITICAL9.2PL ✓same product

Brak autoryzacji w Pterodactyl Wings — dostęp do danych serwerów innych węzłów

CVE-2024-27102CRITICAL9.9PL ✓same product

Path Traversal w Pterodactyl Wings — dostęp do plików poza sandbox

CVE-2023-32080CRITICAL9.0PL ✓same product

Pterodactyl Wings — privilege escalation do systemu hosta przez skrypty instalacyjne

CVE-2023-25168CRITICAL9.6PL ✓same product

Pterodactyl Wings — rekurencyjne usuwanie plików na systemie hosta

CVE-2025-69199HIGH8.3same product

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to ...