FlawAtlas
Search the atlas
CVE-2025-68954 High

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

Exploit probability 0.2%
Published January 12, 2026
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

82 explicit affected versions

Go github.com/pterodactyl/wings
Go github.com/pterodactyl/wings
Packagist pterodactyl/panel

118 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-68954

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.

View original source
Open Source Vulnerabilities GO-2026-4283

Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced in github.com/pterodactyl/wings

View original source
Open Source Vulnerabilities GHSA-8c39-xppg-479c

### Summary Pterodactyl does not revoke _active_ SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. ### Details When a user opens a connection to a server using the Wings SFTP server instance the permissions are checked and returned from the authentication API call made to the Panel. However, credentials are not checked again after the initial handshake. Thus, if a user is removed from a server in the panel or have their permissions modified, those permissions are not updated in the SFTP connection. As a result, a user that has already gained access to a server's files via the SFTP subsystem will maintain those permissions until disconnected (via Wings restart, or a manual disconnection on their end). > [!NOTE] > > This issue impacts the SFTP subsystem for server files specifically. There is no exposure of Wings private data, or any data outside of a server's local filesystem. Additionally, a user must have been _connected to SFTP at the time of their permissions being revoked_ in order for this issue to be exploited. If a user was not connected, they would not be able to connect once their permissions were reduced. ### Fix Please upgrade to `[email protected]` and `[email protected]` to resolve this issue. Patches are available via the implementation PRs, but it is recommended to apply by upgrading the entire instance.

View original source

05 / REFERENCES

Further evidence