{"schema_version":1,"title":"pterodactyl/panel (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in pterodactyl/panel (Packagist): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-61609, was published on 28 July 2026.","url":"https://junglewise.ai/threats/technologies/pterodactyl-panel","json_url":"https://junglewise.ai/threats/technologies/pterodactyl-panel.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pterodactyl-panel","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":19,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":11},"latest":[{"cve":"CVE-2026-61609","cvss":7.5,"epss":0.0074,"slug":"cve-2026-61609-pterodactyl-panel-authentication-denial-of-service-in-login-rate","title":"Pterodactyl Panel authentication denial of service in login rate limiter","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:28.693+00:00","url":"https://junglewise.ai/threats/cve-2026-61609-pterodactyl-panel-authentication-denial-of-service-in-login-rate"},{"cve":"CVE-2026-54593","cvss":8.1,"epss":0.0068,"slug":"cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope","title":"Pterodactyl Panel and Wings privilege escalation via JWT scope reuse","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:00.097+00:00","url":"https://junglewise.ai/threats/cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope"},{"cvss":4,"slug":"pterodactyl-panel-client-email-change-endpoint-allows-enumeration-of-19f88139","title":"Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system","severity":"medium","exploited":false,"published_at":"2026-06-26T20:54:38+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-client-email-change-endpoint-allows-enumeration-of-19f88139"},{"cvss":5.5,"slug":"pterodactyl-panel-user-enumeration-in-account-email-update-endpoint-89a5a182","title":"Pterodactyl Panel user enumeration in account email update endpoint","severity":"medium","exploited":false,"published_at":"2026-06-26T20:54:38+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-user-enumeration-in-account-email-update-endpoint-89a5a182"},{"cve":"CVE-2026-35202","cvss":4,"epss":0.0035,"slug":"cve-2026-35202-pterodactyl-panel-race-condition-in-databasecontroller-resource","title":"Pterodactyl Panel race condition in DatabaseController resource limits","severity":"medium","exploited":false,"published_at":"2026-06-02T20:16:35.143+00:00","url":"https://junglewise.ai/threats/cve-2026-35202-pterodactyl-panel-race-condition-in-databasecontroller-resource"},{"cve":"CVE-2026-26016","cvss":4,"epss":0.0047,"slug":"cve-2026-26016-pterodactyl-panel-allows-cross-node-server-configuration","title":"Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization","severity":"medium","exploited":false,"published_at":"2026-02-17T18:54:49+00:00","url":"https://junglewise.ai/threats/cve-2026-26016-pterodactyl-panel-allows-cross-node-server-configuration"},{"cvss":4,"slug":"pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0","title":"Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change","severity":"medium","exploited":false,"published_at":"2026-02-17T17:15:18+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0"},{"cve":"CVE-2025-69198","cvss":3.1,"epss":0.0024,"slug":"cve-2025-69198-pterodactyl-improperly-locks-resources-allowing-raced-queries-to","title":"Pterodactyl improperly locks resources allowing raced queries to create more resources than alloted","severity":"low","exploited":false,"published_at":"2026-01-20T16:30:17+00:00","url":"https://junglewise.ai/threats/cve-2025-69198-pterodactyl-improperly-locks-resources-allowing-raced-queries-to"},{"cve":"CVE-2025-68954","cvss":4,"epss":0.0025,"slug":"cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or","title":"GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings","severity":"medium","exploited":false,"published_at":"2026-01-12T17:39:39+00:00","url":"https://junglewise.ai/threats/cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or"},{"cve":"CVE-2025-69197","cvss":3.1,"epss":0.0036,"slug":"cve-2025-69197-pterodactyl-totps-can-be-reused-during-validity-window","title":"Pterodactyl TOTPs can be reused during validity window","severity":"low","exploited":false,"published_at":"2026-01-06T17:20:57+00:00","url":"https://junglewise.ai/threats/cve-2025-69197-pterodactyl-totps-can-be-reused-during-validity-window"},{"cvss":4,"slug":"pterodactyl-has-a-reflected-xss-vulnerability-in-create-new-database-3f28f7b5","title":"Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”","severity":"medium","exploited":false,"published_at":"2025-12-30T15:13:52+00:00","url":"https://junglewise.ai/threats/pterodactyl-has-a-reflected-xss-vulnerability-in-create-new-database-3f28f7b5"},{"cve":"CVE-2025-49132","cvss":3.1,"epss":0.5446,"slug":"cve-2025-49132-pterodactyl-panel-allows-unauthenticated-arbitrary-remote-code","title":"Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution","severity":"low","exploited":false,"published_at":"2025-06-19T19:55:27+00:00","url":"https://junglewise.ai/threats/cve-2025-49132-pterodactyl-panel-allows-unauthenticated-arbitrary-remote-code"},{"cve":"CVE-2024-49762","cvss":3.1,"epss":0.0014,"slug":"cve-2024-49762-pterodactyl-panel-has-plain-text-logging-of-user-passwords-when","title":"Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled","severity":"low","exploited":false,"published_at":"2024-10-24T19:07:03+00:00","url":"https://junglewise.ai/threats/cve-2024-49762-pterodactyl-panel-has-plain-text-logging-of-user-passwords-when"},{"cve":"CVE-2024-34067","cvss":3.1,"epss":0.0046,"slug":"cve-2024-34067-pterodactyl-panel-s-admin-area-vulnerable-to-cross-site-scripting","title":"Pterodactyl panel's admin area vulnerable to Cross-site Scripting","severity":"low","exploited":false,"published_at":"2024-05-03T20:29:04+00:00","url":"https://junglewise.ai/threats/cve-2024-34067-pterodactyl-panel-s-admin-area-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2019-1020002","cvss":3,"epss":0.0148,"slug":"cve-2019-1020002-pterodactyl-vulnerable-to-2fa-sniffing","title":"Pterodactyl vulnerable to 2FA Sniffing","severity":"low","exploited":false,"published_at":"2022-05-24T16:51:37+00:00","url":"https://junglewise.ai/threats/cve-2019-1020002-pterodactyl-vulnerable-to-2fa-sniffing"},{"cvss":3.1,"slug":"insufficient-session-expiration-in-pterodactyl-api-ea670f23","title":"Insufficient Session Expiration in Pterodactyl API","severity":"low","exploited":false,"published_at":"2022-01-21T18:43:05+00:00","url":"https://junglewise.ai/threats/insufficient-session-expiration-in-pterodactyl-api-ea670f23"},{"cve":"CVE-2021-41273","cvss":3.1,"epss":0.0039,"slug":"cve-2021-41273-cross-site-request-forgery-allowing-sending-of-test-emails-and","title":"Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys","severity":"low","exploited":false,"published_at":"2021-11-18T15:46:57+00:00","url":"https://junglewise.ai/threats/cve-2021-41273-cross-site-request-forgery-allowing-sending-of-test-emails-and"},{"cve":"CVE-2021-41176","cvss":3.1,"epss":0.0052,"slug":"cve-2021-41176-pterodactyl-panel-csrf-allowing-an-external-page-to-trigger-a","title":"pterodactyl/panel CSRF allowing an external page to trigger a user logout event","severity":"low","exploited":false,"published_at":"2021-10-25T19:42:46+00:00","url":"https://junglewise.ai/threats/cve-2021-41176-pterodactyl-panel-csrf-allowing-an-external-page-to-trigger-a"},{"cve":"CVE-2021-41129","cvss":3.1,"epss":0.0175,"slug":"cve-2021-41129-pterodactyl-panel-vulnerable-to-authentication-bypass-due-to","title":"Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification","severity":"low","exploited":false,"published_at":"2021-10-04T20:14:13+00:00","url":"https://junglewise.ai/threats/cve-2021-41129-pterodactyl-panel-vulnerable-to-authentication-bypass-due-to"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"pterodactyl/panel (Packagist)","slug":"pterodactyl-panel","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://pterodactyl.io/","repo_url":"https://github.com/pterodactyl/panel","description":"The management panel for Pterodactyl, an open-source game server management platform.","url":"https://junglewise.ai/threats/technologies/pterodactyl-panel"},"most_severe":[{"cve":"CVE-2026-54593","cvss":8.1,"epss":0.0068,"slug":"cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope","title":"Pterodactyl Panel and Wings privilege escalation via JWT scope reuse","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:00.097+00:00","url":"https://junglewise.ai/threats/cve-2026-54593-pterodactyl-panel-and-wings-privilege-escalation-via-jwt-scope"},{"cve":"CVE-2026-61609","cvss":7.5,"epss":0.0074,"slug":"cve-2026-61609-pterodactyl-panel-authentication-denial-of-service-in-login-rate","title":"Pterodactyl Panel authentication denial of service in login rate limiter","severity":"high","exploited":false,"published_at":"2026-07-28T16:19:28.693+00:00","url":"https://junglewise.ai/threats/cve-2026-61609-pterodactyl-panel-authentication-denial-of-service-in-login-rate"},{"cvss":5.5,"slug":"pterodactyl-panel-user-enumeration-in-account-email-update-endpoint-89a5a182","title":"Pterodactyl Panel user enumeration in account email update endpoint","severity":"medium","exploited":false,"published_at":"2026-06-26T20:54:38+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-user-enumeration-in-account-email-update-endpoint-89a5a182"},{"cve":"CVE-2026-26016","cvss":4,"epss":0.0047,"slug":"cve-2026-26016-pterodactyl-panel-allows-cross-node-server-configuration","title":"Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization","severity":"medium","exploited":false,"published_at":"2026-02-17T18:54:49+00:00","url":"https://junglewise.ai/threats/cve-2026-26016-pterodactyl-panel-allows-cross-node-server-configuration"},{"cve":"CVE-2026-35202","cvss":4,"epss":0.0035,"slug":"cve-2026-35202-pterodactyl-panel-race-condition-in-databasecontroller-resource","title":"Pterodactyl Panel race condition in DatabaseController resource limits","severity":"medium","exploited":false,"published_at":"2026-06-02T20:16:35.143+00:00","url":"https://junglewise.ai/threats/cve-2026-35202-pterodactyl-panel-race-condition-in-databasecontroller-resource"},{"cve":"CVE-2025-68954","cvss":4,"epss":0.0025,"slug":"cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or","title":"GO-2026-4283 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings","severity":"medium","exploited":false,"published_at":"2026-01-12T17:39:39+00:00","url":"https://junglewise.ai/threats/cve-2025-68954-pterodactyl-does-not-revoke-sftp-access-when-server-is-deleted-or"},{"cvss":4,"slug":"pterodactyl-panel-client-email-change-endpoint-allows-enumeration-of-19f88139","title":"Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system","severity":"medium","exploited":false,"published_at":"2026-06-26T20:54:38+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-client-email-change-endpoint-allows-enumeration-of-19f88139"},{"cvss":4,"slug":"pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0","title":"Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change","severity":"medium","exploited":false,"published_at":"2026-02-17T17:15:18+00:00","url":"https://junglewise.ai/threats/pterodactyl-panel-s-sftp-sessions-remain-active-after-user-account-fdf64de0"},{"cvss":4,"slug":"pterodactyl-has-a-reflected-xss-vulnerability-in-create-new-database-3f28f7b5","title":"Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”","severity":"medium","exploited":false,"published_at":"2025-12-30T15:13:52+00:00","url":"https://junglewise.ai/threats/pterodactyl-has-a-reflected-xss-vulnerability-in-create-new-database-3f28f7b5"},{"cve":"CVE-2025-49132","cvss":3.1,"epss":0.5446,"slug":"cve-2025-49132-pterodactyl-panel-allows-unauthenticated-arbitrary-remote-code","title":"Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution","severity":"low","exploited":false,"published_at":"2025-06-19T19:55:27+00:00","url":"https://junglewise.ai/threats/cve-2025-49132-pterodactyl-panel-allows-unauthenticated-arbitrary-remote-code"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}