Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocations. This happens because the database locking mechanism used in the controllers is totally broken and doesn't actually lock anything. Version 1.12.3 patches the issue. | |
| Title | Pterodactyl has a database resource limit bypass via race condition in Client API | |
| Weaknesses | CWE-367 CWE-770 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T19:03:46.792Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35202
No data.
Status : Received
Published: 2026-06-02T20:16:35.143
Modified: 2026-06-02T20:16:35.143
Link: CVE-2026-35202
No data.
OpenCVE Enrichment
No data.