cvedb.io
CVE-2021-41129
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2021-10-06T20:15:19.897 · Last modified 2026-06-17T04:07:55.830

Summary

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious actor to authenticate as a random user in the Panel. The malicious user must target an account with two-factor authentication enabled, and then must provide a correct two-factor authentication token before being authenticated as that user. Due to a validation flaw in the logic handling user authentication during the two-factor authentication process a malicious user can trick the system into loading credentials for an arbitrary user by modifying the token sent to the server. Thi

Affected products

pterodactyl — panel

Does this affect you?

Add your gear to cvedb and we'll alert you only when pterodactyl ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.