Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pterodactyl

First CVE: Jul 29, 2019Active for: 7 yearsTotal CVEs: 18
27.2
VTI Score
Low

Pterodactyl operates a widely used game-server management platform consisting of a web control panel and distributed daemon (Wings) that handle authentication, resource allocation, and server orchestration for game hosting. The vendor's vulnerability pattern centers on authentication and access-control weaknesses—including authorization bypasses, CSRF, and improper authentication mechanisms—alongside resource-consumption flaws endemic to multi-tenant server orchestration, reflecting the trust boundaries and rate-limiting demands of its infrastructure role. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pterodactyl over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-26016HIGH
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers
Feb 19, 20268.127NONO
CVE-2023-32080HIGH
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected v
May 10, 20238.826NONO
CVE-2023-25152HIGH
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that
Feb 8, 20238.826NONO
CVE-2021-41129HIGH
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-
Oct 6, 20218.126NONO
CVE-2025-69198MEDIUM
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocati
Jan 19, 20266.525NONO
CVE-2023-25168HIGH
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with
Feb 9, 20238.225NONO
CVE-2024-27102HIGH
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to acce
Mar 13, 20248.524NONO
CVE-2024-34066HIGH
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an
May 3, 20248.423NONO
CVE-2019-1020002HIGH
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
Jul 29, 20197.523NONO
CVE-2026-21696MEDIUM
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider
Jan 19, 20266.522NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
56%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (5.6%)
Network17 (94.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (77.8%)
High4 (22.2%)
Unknown0 (0.0%)
User Interaction
None14 (77.8%)
Unknown0 (0.0%)
Required4 (22.2%)
Privileges Required
Low11 (61.1%)
High1 (5.6%)
None6 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pterodactyl.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pterodactyl — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pterodactyl's Products

View all 2 CNAs →

Top CWEs