VendorsPterodactylpanelany version
Vulnerabilities

Pterodactyl Panel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-26016
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Published 2026-02-19 · Analyzed
9.2EPSS 0.005
CVE-2021-41129
Authentication bypass in Pterodactyl
Published 2021-10-06 · Modified
8.1EPSS 0.018
CVE-2019-1020002
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
Published 2019-07-29 · Modified
7.5EPSS 0.015
CVE-2025-68954
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
Published 2026-01-06 · Analyzed
7.5EPSS 0.002
CVE-2025-69197
Pterodactyl TOTPs can be reused during validity window
Published 2026-01-06 · Analyzed
6.5EPSS 0.004
CVE-2025-69198
Pterodactyl's improper resource locking allows raced queries to create more resources than alloted
Published 2026-01-19 · Analyzed
6.5EPSS 0.002
CVE-2024-34067
Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel
Published 2024-05-03 · Analyzed
6.1EPSS 0.005
CVE-2021-41176
logout CSRF in Pterodactyl Panel
Published 2021-10-25 · Modified
4.3EPSS 0.005
CVE-2021-41273
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
Published 2021-11-17 · Modified
4.3EPSS 0.004