PT-2026-3490 · Pterodactyl · Wings

Danny6167

·

Publicado

2026-01-19

·

Atualizado

2026-02-06

·

CVE-2026-21696

CVSS v4.0

8.3

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Wings versions 1.7.0 through 1.11.9
Description Wings, the server control plane for Pterodactyl, is affected by an issue where it does not account for SQLite’s maximum parameter limit when handling activity log entries. This allows a low-privileged user to cause the panel to be flooded with activity records. The system attempts to delete activity entries from the SQLite database in a single query, exceeding the limit of 32766 parameters. This results in an error, preventing the deletion of entries, which are then repeatedly re-processed and sent to the panel. An attacker can exploit this to repeatedly upload the same activity data to the panel, potentially exhausting the database server’s disk space.
Recommendations Update to Wings version 1.12.0 or later.

Exploit

Correção

Resource Exhaustion

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21696
GHSA-2497-GP99-2M74
GO-2026-4329
SUSE-SU-2026:0403-1

Produtos afetados

Wings