Home/Product/pterodactyl wings
Product

pterodactyl wings

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-21696
>= 1.7.0 and < 1.12.0
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and
6.5MEDIUM
CVE-2025-69199
< 1.12.0
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, webs
6.5MEDIUM
CVE-2025-68954
< 1.12.0
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections
5.4MEDIUM
CVE-2024-34068
< 1.11.2
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able
6.4MEDIUM
CVE-2024-34066
< 1.11.2
Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node confi
8.4HIGH
CVE-2024-27102
< 1.11.9
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings.
9.9CRITICAL
CVE-2023-32080
< 1.7.4
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 pri
9.0CRITICAL
CVE-2023-25168
>= 1.7.0 and < 1.7.4
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the hos
9.6CRITICAL
CVE-2023-25152
< 1.7.3
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new file
8.4HIGH
CVE-2021-32699
< 1.4.4
Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prio
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin