PKSA-hhbv-vvdq-cchz Security Advisory
-
[HIGH] Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
PKSA-hhbv-vvdq-cchz CVE-2026-54593 GHSA-8r6w-3qq5-4p4r
Affected package: pterodactyl/panel
Affected version: <1.12.3
Reported by:
GitHub