What is CVE-2026-54593?
CVE-2026-54593 is a JWT validation flaw in the Wings component of the Pterodactyl game server management panel, where the `/upload/file` endpoint accepted any panel-signed JWT without checking its intended purpose. It affects versions before Panel 1.12.3 and Wings 1.12.2. Upgrading to the fixed versions is recommended.
Azərbaycanca: CVE-2026-54593 Pterodactyl oyun server idarəetmə panelində Wings komponentinin `/upload/file` endpointində JWT token yoxlanışı zəifliyidir. Bu, Panel 1.12.3 və Wings 1.12.2 öncəsi versiyalara təsir edir. Dərhal qeyd olunan versiyalara yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions are affected by CVE-2026-54593?
This vulnerability affects versions before Panel 1.12.3 and Wings 1.12.2.
What is the root cause of CVE-2026-54593?
The flaw stems from the `/upload/file` endpoint accepting any panel-signed JWT without checking its intended purpose.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.