Junglewise Threat Intelligence

CVE-2026-26016: Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

CVE-2026-26016 · Severity: medium · CVSS 4 · Published 2026-02-17

Technologies: pterodactyl/panel (Packagist). Vendors: Packagist.

Executive brief

Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization

Affected products

  • Packagist pterodactyl/panel

Related threats