PT-2026-1361 · Unknown · Pterodactyl

Published

2026-01-06

·

Updated

2026-01-06

·

CVE-2025-69197

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pterodactyl versions 1.11.11 and below
Description Pterodactyl, a game server management panel, has an issue where Time-based One-Time Password (TOTP) can be reused during its validity window. When a user with two-factor authentication (2FA) enabled signs in, the system does not properly mark the entered token as used. This allows an attacker who has intercepted a valid TOTP token, such as during a screen share, to use it multiple times in conjunction with a known username and password within the 60-second validity period of the token.
Recommendations Update to version 1.12.0 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-69197
GHSA-RGMP-4873-R683

Affected Products

Pterodactyl