CVE-2025-69197: Pterodactyl TOTPs can be reused during validity window

Published Jan 6, 2026
·
Updated

Summary When a user signs into an account with 2FA enabled they are prompted to enter a token. When that token is used, it is not sufficiently marked as used in the system allowing an attacker that intercepts that token to then use it in addition to a known username/password during the token validity window.

This vulnerability requires that an attacker already be in possession of a valid username and password combination, and intercept a valid 2FA token (for example, during a screen share). The token must then be provided in addition to the username and password during the limited token validity window. The validity window is ~60 seconds as the Panel allows at most one additional window to the current one, each window being 30 seconds.

Other sources

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in the system. This allows an attacker who intercepts that token to use it in addition to a known username/password during the 60-second token validity window. The attacker must have intercepted a valid 2FA token (for example, during a screen share). This issue is fixed in version 1.12.0.

MITRE

Affected Software

3 affected componentsFixes available
pypi/pterodactyl<=1.11.11
composer/pterodactyl/panel<1.12.0
1.12.0
pterodactyl panel<1.12.0

Event History

Jan 6, 2026
CVE Published
via MITRE·12:44 AM
Data Sourced
via MITRE·12:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·05:20 PM
Data Sourced
via GitHub·05:20 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-69197?

CVE-2025-69197 is classified as a medium severity vulnerability due to its potential to allow unauthorized access through repeated use of valid TOTP tokens.

2

How do I fix CVE-2025-69197?

To fix CVE-2025-69197, upgrade to Pterodactyl version 1.12.0 or later which addresses the vulnerability.

3

What versions of Pterodactyl are affected by CVE-2025-69197?

Pterodactyl versions 1.11.11 and below are affected by CVE-2025-69197.

4

What vulnerability does CVE-2025-69197 introduce?

CVE-2025-69197 introduces a weakness that allows tokens used for two-factor authentication to be reused within their validity period.

5

Is two-factor authentication secure in versions affected by CVE-2025-69197?

Two-factor authentication is compromised in affected versions of Pterodactyl as tokens can be reused, which poses a security risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203