GHSA-8r6w-3qq5-4p4r: Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
highvulnerability
security
Summary
Pterodactyl, a game server management platform, has a privilege escalation vulnerability where the Wings component (the server control software) improperly validates JWTs (JSON Web Tokens, which are digitally signed credentials that prove identity). A subuser can reuse a JWT token meant for a lower-privilege action like viewing a console or downloading files to upload arbitrary files to a server without having explicit file upload permissions.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
July 28, 2026
Classification
Attack SophisticationModerate
Affected Packages
github.com/pterodactyl/wings@< 1.12.2 (fixed: 1.12.2)pterodactyl/panel@< 1.12.3 (fixed: 1.12.3)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-8r6w-3qq5-4p4r
First tracked: July 28, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%