Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-86177: Pterodactyl Panel lets subusers run unauthorized commands
CVE-2026-86177 · published 1 month ago
Summary
The Pterodactyl Panel (versions before 1.14.1) does not correctly check permissions when a subuser creates a scheduled task. This lets a subuser who can only edit schedules run any console command, change server power state, or start backups without proper approval. Update the Panel to version 1.14.1 or later, or restrict subuser permissions until the fix is applied.
What to do
- Update pterodactyl panel to version 1.14.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| pterodactyl | panel | < 1.14.1 |
Original advisory text
Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
References
- https://github.com/pterodactyl/panel
- https://github.com/pterodactyl/panel/blob/v1.14.0/app/Http/Requests/Api/Client/S...
- https://github.com/pterodactyl/panel/commit/913b354aff43ff04fce95357ed68a675a1dd...
- https://github.com/pterodactyl/panel/releases/tag/v1.14.1
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86177... Vendor Advisory
- https://www.vulncheck.com/advisories/pterodactyl-panel-before-1.14.1-privilege-e...
- https://nvd.nist.gov/vuln/detail/CVE-2026-86177 Vendor Advisory
- https://github.com/pterodactyl/panel/blob/v1.14.0/app/Jobs/Schedule/RunTaskJob.p...
- https://github.com/geo-chen/oss/blob/main/panel.md
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-862Missing Authorization
Timeline
Published5 Sep 2026
Updated9 Oct 2026
First seen5 Sep 2026
Track software like this
Free during beta