Vulnerability Description
Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-35202?
CVE-2026-35202 is a documented vulnerability. Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocati...
How severe is CVE-2026-35202?
CVSS scoring is not yet available for CVE-2026-35202. Check NVD for updates.
Is there a patch for CVE-2026-35202?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.