🚨 CVE-2026-86177
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
🎖@cveNotify

GitHub
oss/panel.md at main · geo-chen/oss
securing oss responsibly. Contribute to geo-chen/oss development by creating an account on GitHub.
September 5, 2026 40