Technology · Packagist
pterodactyl/panel (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in pterodactyl/panel (Packagist): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-61609, was published on 28 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 0
- Exploited in the wild
- 0
About pterodactyl/panel (Packagist)
The management panel for Pterodactyl, an open-source game server management platform.
Latest pterodactyl/panel (Packagist) vulnerabilities
- CVE-2026-61609: Pterodactyl Panel authentication denial of service in login rate limiterhighCVSS 7.5EPSS 0.7%
- CVE-2026-54593: Pterodactyl Panel and Wings privilege escalation via JWT scope reusehighCVSS 8.1EPSS 0.7%
- Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in systemmediumCVSS 4
- Pterodactyl Panel user enumeration in account email update endpointmediumCVSS 5.5
- CVE-2026-35202: Pterodactyl Panel race condition in DatabaseController resource limitsmediumCVSS 4EPSS 0.4%
- CVE-2026-26016: Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing AuthorizationmediumCVSS 4EPSS 0.5%
- Pterodactyl Panel's SFTP sessions remain active after user account deletion or password changemediumCVSS 4
- CVE-2025-69198: Pterodactyl improperly locks resources allowing raced queries to create more resources than allotedlowCVSS 3.1EPSS 0.2%
- CVE-2025-68954: GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in…mediumCVSS 4EPSS 0.3%
- CVE-2025-69197: Pterodactyl TOTPs can be reused during validity windowlowCVSS 3.1EPSS 0.4%
- Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”mediumCVSS 4
- CVE-2025-49132: Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code ExecutionlowCVSS 3.1EPSS 54.5%
- CVE-2024-49762: Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabledlowCVSS 3.1EPSS 0.1%
- CVE-2024-34067: Pterodactyl panel's admin area vulnerable to Cross-site ScriptinglowCVSS 3.1EPSS 0.5%
- CVE-2019-1020002: Pterodactyl vulnerable to 2FA SniffinglowCVSS 3EPSS 1.5%
- Insufficient Session Expiration in Pterodactyl APIlowCVSS 3.1
- CVE-2021-41273: Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keyslowCVSS 3.1EPSS 0.4%
- CVE-2021-41176: pterodactyl/panel CSRF allowing an external page to trigger a user logout eventlowCVSS 3.1EPSS 0.5%
- CVE-2021-41129: Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verificationlowCVSS 3.1EPSS 1.8%
Most severe pterodactyl/panel (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54593: Pterodactyl Panel and Wings privilege escalation via JWT scope reusehighCVSS 8.1EPSS 0.7%
- CVE-2026-61609: Pterodactyl Panel authentication denial of service in login rate limiterhighCVSS 7.5EPSS 0.7%
- Pterodactyl Panel user enumeration in account email update endpointmediumCVSS 5.5
- CVE-2026-26016: Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing AuthorizationmediumCVSS 4EPSS 0.5%
- CVE-2026-35202: Pterodactyl Panel race condition in DatabaseController resource limitsmediumCVSS 4EPSS 0.4%
- CVE-2025-68954: GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in…mediumCVSS 4EPSS 0.3%
- Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in systemmediumCVSS 4
- Pterodactyl Panel's SFTP sessions remain active after user account deletion or password changemediumCVSS 4
- Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”mediumCVSS 4
- CVE-2025-49132: Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code ExecutionlowCVSS 3.1EPSS 54.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pterodactyl-panel.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pterodactyl/panel (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/pterodactyl-panel, 28 September 2026.