A vulnerability was found in Pterodactyl panel up to 1.12.99. It has been classified as problematic. This affects the function
RouteServiceProvider::configureRateLimiting of the component Authentication Rate Limiter. Performing a manipulation results in resource consumption.
This vulnerability was named CVE-2026-61609. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.