PT-2026-3490 · Pterodactyl · Wings

Danny6167

·

Published

2026-01-19

·

Updated

2026-02-06

·

CVE-2026-21696

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Wings versions 1.7.0 through 1.11.9
Description Wings, the server control plane for Pterodactyl, is affected by an issue where it does not account for SQLite’s maximum parameter limit when handling activity log entries. This allows a low-privileged user to cause the panel to be flooded with activity records. The system attempts to delete activity entries from the SQLite database in a single query, exceeding the limit of 32766 parameters. This results in an error, preventing the deletion of entries, which are then repeatedly re-processed and sent to the panel. An attacker can exploit this to repeatedly upload the same activity data to the panel, potentially exhausting the database server’s disk space.
Recommendations Update to Wings version 1.12.0 or later.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-21696
GHSA-2497-GP99-2M74
GO-2026-4329
SUSE-SU-2026:0403-1

Affected Products

Wings