Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8c39-xppg-479c | Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced |
Mon, 12 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pterodactyl wings
|
|
| CPEs | cpe:2.3:a:pterodactyl:panel:*:*:*:*:*:*:*:* cpe:2.3:a:pterodactyl:wings:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Pterodactyl wings
|
|
| Metrics |
cvssV3_1
|
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pterodactyl
Pterodactyl panel |
|
| Vendors & Products |
Pterodactyl
Pterodactyl panel |
Tue, 06 Jan 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0. | |
| Title | Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-06T19:01:17.178Z
Reserved: 2025-12-26T21:39:55.482Z
Link: CVE-2025-68954
Updated: 2026-01-06T14:23:46.508Z
Status : Analyzed
Published: 2026-01-06T01:16:01.387
Modified: 2026-01-12T21:29:12.877
Link: CVE-2025-68954
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:16:13Z
Github GHSA