Executive brief
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Affected products
- Packagist pterodactyl/panel
Junglewise Threat Intelligence
CVE-2026-26016 · Severity: medium · CVSS 4 · Published 2026-02-17
Technologies: pterodactyl/panel (Packagist). Vendors: Packagist.
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization