SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86177

HIGH · CVSS 8.8 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Pterodactyl Panel versions prior to 1.14.1 are vulnerable due to inadequate validation of permissions during scheduled task creation, enabling subusers with limited permissions to execute arbitrary console commands. This flaw allows unauthorized execution of critical tasks, such as controlling server power states or creating backups, posing significant risks to server integrity and security. Organizations utilizing Pterodactyl Panel should prioritize patching to mitigate potential exploitation of this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86177
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.