CVE-2026-52855
Pterodactyl · Wings
A vulnerability in Pterodactyl Wings allows authenticated users to read sensitive configuration tokens and registry credentials from daemon configuration files.
Executive summary
A critical vulnerability in Pterodactyl Wings permits low privileged users to extract sensitive authentication tokens and docker credentials, posing a high risk of total system compromise.
Vulnerability
This vulnerability involves improper handling of configuration placeholders (CWE-200) within egg templates, which allows an authenticated user with low privileges to access sensitive daemon configuration data, including tokens and registry credentials.
Business impact
Successful exploitation grants an attacker access to highly sensitive credentials that govern the interaction between the management panel and the underlying infrastructure. With these tokens, an attacker could potentially escalate privileges, gain unauthorized control over game servers, or manipulate container registries, leading to severe data exposure and full service disruption. The CVSS score of 9.9 reflects the critical nature of this unauthorized access to administrative secrets.
Remediation
Immediate Action: Update the Pterodactyl Wings installation to version 1.12.3 or later immediately to address the configuration parsing flaw.
Proactive Monitoring: Review access logs for suspicious requests originating from low privileged user accounts that target configuration or management API endpoints.
Compensating Controls: Ensure that the Pterodactyl management environment is restricted to trusted internal networks and utilize egress filtering to prevent unauthorized exfiltration of sensitive configuration tokens.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates an immediate update to version 1.12.3. Organizations utilizing Pterodactyl Wings should prioritize this patch to prevent unauthorized access to critical infrastructure credentials and maintain the integrity of their game server management environment.