Description
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
Published: 2026-09-05
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Pterodactyl Panel before version 1.14.1 allows a subuser account that has only the schedule.update permission to create and immediately trigger scheduled tasks that run arbitrary console commands on the game server. By exploiting this missing permission check, an attacker can execute any server‑side command, toggle power state, or initiate backups without proper authorization. This grants the attacker control equivalent to that of a full administrator on the affected server.

Affected Systems

Pterodactyl Panel versions prior to 1.14.1 are impacted. Users who employ subuser accounts with schedule.update privileges can be compromised, regardless of which specific game server instance they target.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity vulnerability. Because the EPSS score is not available, no recent exploitation data is reported, and the vulnerability is not currently listed in the CISA KEV catalog, the immediate risk depends on the presence of subusers with schedule.update permissions. An authenticated subuser can exploit the flaw, making the attack vector effectively an authenticated, privilege‑escalation attack. Once triggered, the attacker can execute arbitrary commands on the underlying host, potentially compromising the entire system if the framework grants full root access to the console manager.

Generated by OpenCVE AI on September 5, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pterodactyl Panel to version 1.14.1 or later, which includes a fix for the permission check.
  • Revoke the schedule.update permission from all subuser accounts until the upgrade is completed, ensuring only administrators can create or trigger tasks.
  • Audit subuser permission assignments to enforce the principle of least privilege; remove any unnecessary task‑related permissions to limit future attack surfaces.

Generated by OpenCVE AI on September 5, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
Title Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks
First Time appeared Pterodactyl
Pterodactyl panel
Weaknesses CWE-862
CPEs cpe:2.3:a:pterodactyl:panel:*:*:*:*:*:*:*:*
Vendors & Products Pterodactyl
Pterodactyl panel
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pterodactyl Panel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-05T11:01:28.077Z

Reserved: 2026-09-05T10:40:41.335Z

Link: CVE-2026-86177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T11:16:46.397

Modified: 2026-09-05T11:16:46.397

Link: CVE-2026-86177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T13:30:05Z

Weaknesses