Security Advisory

CVE-2026-86177

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-05 11:01:28
Last updated 2026-09-08 18:14:11
Assigner VulnCheck
CVSS score 8.8
State PUBLISHED

Description

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.