Pterodactyl operates a widely used game-server management platform consisting of a web control panel and distributed daemon (Wings) that handle authentication, resource allocation, and server orchestration for game hosting. The vendor's vulnerability pattern centers on authentication and access-control weaknesses—including authorization bypasses, CSRF, and improper authentication mechanisms—alongside resource-consumption flaws endemic to multi-tenant server orchestration, reflecting the trust boundaries and rate-limiting demands of its infrastructure role. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pterodactyl over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26016HIGH Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers | Feb 19, 2026 | 8.1 | 27 | NO | NO |
CVE-2023-32080HIGH Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected v | May 10, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-25152HIGH Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that | Feb 8, 2023 | 8.8 | 26 | NO | NO |
CVE-2021-41129HIGH Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two- | Oct 6, 2021 | 8.1 | 26 | NO | NO |
CVE-2025-69198MEDIUM Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocati | Jan 19, 2026 | 6.5 | 25 | NO | NO |
CVE-2023-25168HIGH Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with | Feb 9, 2023 | 8.2 | 25 | NO | NO |
CVE-2024-27102HIGH Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to acce | Mar 13, 2024 | 8.5 | 24 | NO | NO |
CVE-2024-34066HIGH Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an | May 3, 2024 | 8.4 | 23 | NO | NO |
CVE-2019-1020002HIGH Pterodactyl before 0.7.14 with 2FA allows credential sniffing. | Jul 29, 2019 | 7.5 | 23 | NO | NO |
CVE-2026-21696MEDIUM Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider | Jan 19, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pterodactyl.
Media articles that mention a CVE ID that affects a product developed by Pterodactyl — matched by CVE ID, not by vendor name.