vulns.co
/
GKData.io MCP

Pterodactyl · 1 min read

Pterodactyl: delegated tokens must preserve action-specific authority

GHSA-8r6w-3qq5-4p4r describes an authorization mismatch between the Panel and Wings. Tokens established an authenticated user and server context without adequately separating operation purpose. The maintainer-published report describes an authenticated subuser gaining file-upload authority on an already accessible server despite lacking the required creation permission.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: trusted issuer and valid signature establish token provenance, not authorization for every consumer. Require explicit purpose at issuance and matching operation scope at consumption. Panel 1.12.3 release notes require a scope when generating tokens; Wings 1.12.2 release notes describe verifying subsystem-required scopes. Review the producer and consumer together.

Before reading

  • Basic server-side authorization concepts

Context and limits

  • Requires existing subuser access with a lower-privilege capability such as console connection or downloads. The advisory explicitly excludes users without subuser access to the server. Unauthorized upload is supported; cross-server takeover or command execution is not established here.
  • CVE-2026-54593. The advisory lists Panel before 1.12.3 and Wings before 1.12.2 as affected, with those versions patched. Release notes support the stated remediation design; exact patch implementation and deployed coverage were not independently verified.
  • Published June 6, 2026 by anthonyphysgun; TrixterTheTux is credited as reporter. Product version numbers are not educational-resource editions. No award evidence is claimed.

Sources and provenance

  1. Improper JWT scoping permits uploads without file-creation permission Pterodactyl · reviewed 2026-10-03
  2. Panel v1.12.3 release notes Pterodactyl · reviewed 2026-10-03
  3. Wings v1.12.2 release notes Pterodactyl · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software