CVE-2026-52855

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 17:16

Updated : 2026-09-10 20:12


NVD link : CVE-2026-52855

Mitre link : CVE-2026-52855

CVE.ORG link : CVE-2026-52855


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials