CVE-2026-86177
Received Received - Intake

Pterodactyl Panel Command Execution via Scheduled Tasks

Vulnerability report for CVE-2026-86177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: VulnCheck

Description

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pterodactyl pterodactyl_panel to 1.14.1 (exc)
pterodactyl panel to 1.14.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86177 is a privilege escalation flaw in Pterodactyl Panel versions before 1.14.1. It allows subusers with only schedule.update permission to create and execute arbitrary console commands via scheduled tasks without proper authorization checks. Attackers can trigger tasks immediately to control server power states, run game-server commands, or create backups, bypassing intended access restrictions.

Detection Guidance

To detect this vulnerability, check Pterodactyl Panel versions before 1.14.1. Verify if subusers with schedule.update permission can create and execute arbitrary console commands. Inspect scheduled tasks for unexpected commands, power actions, or backups. Review logs for unauthorized task executions.

Impact Analysis

This vulnerability allows attackers with limited permissions to execute unauthorized actions like running arbitrary commands, controlling server power, or creating backups. This could lead to data breaches, unauthorized access to sensitive files, or disruption of game servers. The impact includes privilege escalation and potential compromise of server integrity.

Mitigation Strategies

Upgrade Pterodactyl Panel to version 1.14.1 or later. Review subuser permissions to ensure they only have necessary access. Remove schedule.update permission from users who do not require it. Monitor scheduled tasks for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart