Beveiligingsadvies

CVE-2026-86177

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-05 11:01:28
Laatst bijgewerkt 2026-09-08 18:14:11
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.