GHSA-g7vw-f8p5-c728: Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
criticalvulnerability
security
Summary
A Pterodactyl Panel (server management software) API has a missing authorization check that allows any user with a node secret token (a credential for accessing a specific server cluster) to retrieve configuration data and manipulate servers on other nodes that they shouldn't have access to. This vulnerability requires an attacker to first obtain a node token, but once they do, they can access sensitive server information, installation scripts containing secrets, and even delete servers on other nodes.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.1%
Classification
Attack SophisticationModerate
Affected Packages
pterodactyl/panel@< 1.12.1 (fixed: 1.12.1)
Original source: https://github.com/advisories/GHSA-g7vw-f8p5-c728
First tracked: February 17, 2026 at 02:12 PM
Classified by LLM (prompt v3) · confidence: 95%