PT-2026-3490 · Pterodactyl · Wings
Danny6167
·
Publicado
2026-01-19
·
Atualizado
2026-02-06
·
CVE-2026-21696
CVSS v4.0
8.3
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
Wings versions 1.7.0 through 1.11.9
Description
Wings, the server control plane for Pterodactyl, is affected by an issue where it does not account for SQLite’s maximum parameter limit when handling activity log entries. This allows a low-privileged user to cause the panel to be flooded with activity records. The system attempts to delete activity entries from the SQLite database in a single query, exceeding the limit of 32766 parameters. This results in an error, preventing the deletion of entries, which are then repeatedly re-processed and sent to the panel. An attacker can exploit this to repeatedly upload the same activity data to the panel, potentially exhausting the database server’s disk space.
Recommendations
Update to Wings version 1.12.0 or later.
Exploit
Correção
Resource Exhaustion
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wings