CVE-2025-69197 Details
Description
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not sufficiently marked as used in the system. This allows an attacker who intercepts that token to use it in addition to a known username/password during the 60-second token validity window. The attacker must have intercepted a valid 2FA token (for example, during a screen share). This issue is fixed in version 1.12.0.
A vulnerability in Pterodactyl Panel versions prior to 1.12.0 allows Time-based One-Time Password (TOTP) tokens to be reused within their validity period. When users with two-factor authentication (2FA) enabled sign in, they are prompted to enter a TOTP token. However, once the token is used, it is not properly marked as consumed, enabling an attacker who intercepts the token to use it alongside a known username and password during the token's 60-second validity window. This issue arises because the panel's authentication process does not adequately restrict the use of TOTP tokens after they have been entered, creating a window of opportunity for exploitation.
Users can update to Pterodactyl Panel version 1.12.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pterodactyl panel | < 1.12.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Jan 6, 2026 | New CVE Received | [email protected] |