{ "schema_version": "1.4.0", "id": "GHSA-8r6w-3qq5-4p4r", "modified": "2026-07-28T15:43:25Z", "published": "2026-07-28T15:43:25Z", "aliases": [ "CVE-2026-54593" ], "summary": "Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions", "details": "### Summary\nA privilege escalation vulnerability exists in the Wings /upload/file endpoint due to insufficient validation of panel-signed JWTs. Wings accepts any valid panel-signed JWT containing `server_uuid`, `user_uuid`, and `unique_id`, regardless of the token’s intended purpose. Because the Panel issues JWTs with these same claims for other lower-privilege operations (such as WebSocket authentication and file download links), an authenticated subuser can reuse one of those tokens to upload arbitrary files without possessing the required `file.create` permission.\n\n### Impact\nAny subuser with permission to connect to a server's console, download files, or download backups could reuse those tokens to upload arbitrary files to the _same server_. A user that does not have access to a server as a subuser is not able to arbitrarily upload files.\n\n### Details\nThe panel generated JWT tokens for various purposes:\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Services/Backups/DownloadLinkService.php#L33-L36\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/FileUploadController.php#L45\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/WebsocketController.php#L58-L61\n- https://github.com/pterodactyl/panel/blob/0f82c105201b192d229f6abd5827e2ee7e672a05/app/Http/Controllers/Api/Client/Servers/FileController.php#L82-L85\nThough as the actual purpose is not conveyed part of the JWT tokens, this introduces this vulnerability of being able to do non-intended actions due to the expected fields (i.e. `server_uuid`) on most endpoints being the same when parsing it on wings' side. \n\n### PoC\nCreate a new subuser that has the minimal amount of permissions on a server (`websocket.connect`). As that subuser, retrieve a websocket JWT token from the `GET /api/client/servers/[...]/websocket` endpoint (in my case, I manually just make a request under that user's browser session; you can probably just resend the /websocket request in browser console to get a fresh unused token). Using that websocket token, we can abuse this by directly using it in the `/upload/file` endpoint of the wings node instead of using it for websocket authentication:\n```python3\nimport requests\n\nwings_url = 'http://[...]:8080'\nwebsocket_token = '[...]'\n\nres = requests.post(f'{wings_url}/upload/file', params = {\n 'token': websocket_token,\n}, files = {\n 'files': ('file-upload.txt', b'Hello, World!'),\n})\nprint(res.status_code, res.content)\n```\nObserve, that even though our subuser never has permissions outside viewing the console, they are able to write arbitrary files in the server. This pattern happens in a lot of other action, but this is probably the most interesting one.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], "affected": [ { "package": { "ecosystem": "Packagist", "name": "pterodactyl/panel" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.12.3" } ] } ] }, { "package": { "ecosystem": "Go", "name": "github.com/pterodactyl/wings" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.12.2" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-8r6w-3qq5-4p4r" }, { "type": "WEB", "url": "https://github.com/pterodactyl/panel/pull/5636" }, { "type": "WEB", "url": "https://github.com/pterodactyl/panel/commit/7ffcd636310bb72b54bac3280d2a15e727feded7" }, { "type": "WEB", "url": "https://github.com/pterodactyl/wings/commit/d0ddc80844479302abdaf9654de3bacd511c0f5c" }, { "type": "PACKAGE", "url": "https://github.com/pterodactyl/panel" } ], "database_specific": { "cwe_ids": [ "CWE-1259", "CWE-1270" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2026-07-28T15:43:25Z", "nvd_published_at": null } }