Pterodactyl Wings patched a high-severity flaw, tracked as CVE-2026-52855, that allowed low-privileged users to read sensitive node configuration data through {{config.}} placeholders in egg configuration-file templates. In affected versions prior to 1.12.3, the templating mechanism exposed values from the full daemon configuration, including secrets such as config.token, config.token_id, and Docker registry settings, creating a path for credential disclosure and broader compromise.
The fix, shipped in Wings 1.12.3, changes templating to use a reduced configuration structure instead of the full runtime configuration. The associated code update limits substitutions to a narrower set of Docker-related fields and blocks replacement of entire JSON objects or arrays, allowing only scalar values to be templated. The vulnerability carries a CVSS 3.1 score reflecting network exploitation with low privileges and high impact to confidentiality, integrity, and availability.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability CVE-2026-52855 was newly received by security-advisories@github.com, describing how low-privileged users in Wings versions prior to 1.12.3 could read sensitive daemon configuration values through {{config.}} placeholders in egg configuration-file templates. The disclosure notes the issue is fixed in Wings 1.12.3 and references the fixing commit and GitHub security advisory.
A Pterodactyl Wings commit changed egg templating to use a reduced configuration structure and to block substitution of whole JSON objects or arrays. The patch limits templating exposure to selected Docker network interface values instead of the full daemon configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.