# CVE-2026-52856

## Summary

- **CVE ID:** CVE-2026-52856
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-248, CWE-617, CWE-129, CWE-755
- **Published:** Jul 31, 2026
- **Last Modified:** Jul 31, 2026

## Description

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

## Affected Products

- pterodactyl — wings (< 1.13.0)

## References

- [CNA](https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5)
- [CNA](https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026)
- [CNA](https://github.com/pterodactyl/wings/releases/tag/v1.13.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 26.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._