{"id":"CVE-2026-86177","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86177","summary":"Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary…","details":"Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.","published":"2026-09-05T11:16:46.397","modified":"2026-09-05T11:16:46.397","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/pterodactyl/panel/commit/913b354aff43ff04fce95357ed68a675a1dd0fa6","label":"pterodactyl/panel@913b354"},"references":[{"type":"WEB","url":"https://github.com/geo-chen/oss/blob/main/panel.md"},{"type":"WEB","url":"https://github.com/pterodactyl/panel"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/blob/v1.14.0/app/Http/Requests/Api/Client/Servers/Schedules/StoreTaskRequest.php#L10-L25"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/blob/v1.14.0/app/Jobs/Schedule/RunTaskJob.php#L60-L75"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/commit/913b354aff43ff04fce95357ed68a675a1dd0fa6"},{"type":"WEB","url":"https://github.com/pterodactyl/panel/releases/tag/v1.14.1"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/pterodactyl-panel-before-1.14.1-privilege-escalation-via-schedule-tasks"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-05T11:16:46.397"}}