CVE-2025-68954: Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

Published Jan 6, 2026
·
Updated

Summary Pterodactyl does not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked.

Details When a user opens a connection to a server using the Wings SFTP server instance the permissions are checked and returned from the authentication API call made to the Panel. However, credentials are not checked again after the initial handshake. Thus, if a user is removed from a server in the panel or have their permissions modified, those permissions are not updated in the SFTP connection.

As a result, a user that has already gained access to a server's files via the SFTP subsystem will maintain those permissions until disconnected (via Wings restart, or a manual disconnection on their end).

[!NOTE] This issue impacts the SFTP subsystem for server files specifically. There is no exposure of Wings private data, or any data outside of a server's local filesystem. Additionally, a user must have been connected to SFTP at the time of their permissions being revoked in order for this issue to be exploited. If a user was not connected, they would not be able to connect once their permissions were reduced.

Fix Please upgrade to wings@1.12.0 and panel@1.12.0 to resolve this issue. Patches are available via the implementation PRs, but it is recommended to apply by upgrading the entire instance.

Other sources

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability to be exploited. This issue is fixed in version 1.12.0.

MITRE

Affected Software

5 affected componentsFixes available
npm/pterodactyl<=1.11.11
go/github.com/pterodactyl/wings<1.12.0
1.12.0
composer/pterodactyl/panel<1.12.0
1.12.0
pterodactyl panel<1.12.0
pterodactyl wings<1.12.0

Event History

Jan 6, 2026
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
DescriptionWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·05:18 PM
Data Sourced
via GitHub·05:18 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-68954?

CVE-2025-68954 has a medium severity rating due to the potential for unauthorized access to SFTP connections.

2

How do I fix CVE-2025-68954?

To fix CVE-2025-68954, upgrade to Pterodactyl version 1.12.0 or later where this vulnerability has been addressed.

3

What impact does CVE-2025-68954 have on affected software?

CVE-2025-68954 allows unauthorized users to maintain access to SFTP connections even after their permissions have been revoked.

4

Which versions of Pterodactyl are affected by CVE-2025-68954?

Pterodactyl versions 1.11.11 and below are affected by CVE-2025-68954.

5

Can CVE-2025-68954 be exploited remotely?

Yes, CVE-2025-68954 can be exploited remotely by users who have previously connected via SFTP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203