CVE-2026-86177
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.
- Published Sep 5, 2026
- CVSS 8.7 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available