HIGH 8.1 GitHub
CVE-2026-54593
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
### Summary
A privilege escalation vulnerability exists in the Wings /upload/file endpoint due to insufficient validation of panel-signed JWTs. Wings accepts any valid panel-signed JWT containing `server_uuid`, `user_uuid`, and `unique_id`, regardless of the token’s intended purpose. Because the Panel issues JWTs with these same claims for other lower-privilege operations (such as WebSocket authentication and file download links), an authenticated subuser can reuse one of those tokens to upload
Affected Products
- composer/pterodactyl/panel < 1.12.3
- go/github.com/pterodactyl/wings < 1.12.2
References
- https://github.com/advisories/GHSA-8r6w-3qq5-4p4r
- https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r
- https://github.com/pterodactyl/panel/pull/5636
- https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-07-28 via GitHub. Affected: composer/pterodactyl/panel < 1.12.3, go/github.com/pterodactyl/wings < 1.12.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.