CyberRota Analysis
AI-GeneratedPterodactyl Panel versions prior to 1.14.1 are vulnerable due to inadequate validation of permissions during scheduled task creation, enabling subusers with limited permissions to execute arbitrary console commands. This flaw allows unauthorized execution of critical tasks, such as controlling server power states or creating backups, posing significant risks to server integrity and security. Organizations utilizing Pterodactyl Panel should prioritize patching to mitigate potential exploitation of this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.