Junglewise Threat Intelligence

CVE-2025-68954: GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

CVE-2025-68954 · Severity: medium · CVSS 4 · Published 2026-01-12

Technologies: github.com/pterodactyl/wings (Go), pterodactyl/panel (Packagist). Vendors: Go, Packagist.

Executive brief

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

Affected products

  • Go github.com/pterodactyl/wings
  • Packagist pterodactyl/panel

Related threats