Impact
The flaw in Pterodactyl Panel before version 1.14.1 allows a subuser account that has only the schedule.update permission to create and immediately trigger scheduled tasks that run arbitrary console commands on the game server. By exploiting this missing permission check, an attacker can execute any server‑side command, toggle power state, or initiate backups without proper authorization. This grants the attacker control equivalent to that of a full administrator on the affected server.
Affected Systems
Pterodactyl Panel versions prior to 1.14.1 are impacted. Users who employ subuser accounts with schedule.update privileges can be compromised, regardless of which specific game server instance they target.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity vulnerability. Because the EPSS score is not available, no recent exploitation data is reported, and the vulnerability is not currently listed in the CISA KEV catalog, the immediate risk depends on the presence of subusers with schedule.update permissions. An authenticated subuser can exploit the flaw, making the attack vector effectively an authenticated, privilege‑escalation attack. Once triggered, the attacker can execute arbitrary commands on the underlying host, potentially compromising the entire system if the framework grants full root access to the console manager.
OpenCVE Enrichment