Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-52855.
Unlock with Pro - from £29/user/moDetect Pterodactyl Wings Egg Configuration-File Templating Node Secret Exposure (CVE-2026-52855) in Google Chronicle
Detects exploitation of CVE-2026-52855, a critical (CVSS 9.9) information disclosure vulnerability in Pterodactyl Wings prior to 1.12.3. The Wings daemon's egg configuration-file templating engine fails to properly scope variable substitution, allowing a malicious or crafted egg/server configuration to reference and render node-level secrets (e.g., the Wings daemon token, SFTP credentials, Docker/panel authentication secrets) into server-accessible configuration files. An attacker with the ability to create or modify an egg (via panel admin compromise, supply-chain egg import, or a malicious server owner in multi-tenant environments) can exfiltrate node configuration secrets, leading to full node takeover. Detection focuses on Wings daemon logs showing configuration-file template rendering events that reference sensitive node config keys, unexpected egg install/import activity, and outbound access to rendered server config files containing daemon secrets.
MITRE ATT&CK
YARA-L Detection Query
rule wings_egg_config_secret_exposure {
meta:
author = "df00tech detection engineering"
description = "Detects Wings daemon egg config-file template rendering events exposing node secrets (CVE-2026-52855)"
severity = "CRITICAL"
cve = "CVE-2026-52855"
events:
$log.metadata.event_type = "GENERIC_EVENT"
$log.metadata.product_name = "Pterodactyl Wings"
$log.principal.application = "wings"
re.regex($log.security_result.summary, `(?i)(config-file|egg.*template)`)
re.regex($log.security_result.summary, `(?i)(config\.token|daemon_token|docker\.socket|sftp\.password|authentication_token|panel_secret)`)
condition:
$log
} Chronicle YARA-L rule detecting Wings daemon log events indicating egg config-file templates rendering node secret keys, consistent with CVE-2026-52855 exploitation.
Data Sources
Required Tables
False Positives & Tuning
- Developer or QA debug logging during egg template creation
- Automated CI egg validation pipelines that render config templates
Other platforms for CVE-2026-52855
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Simulate malicious egg config_files template referencing secret key
Expected signal: Wings daemon logs recording config-file template rendering for the test egg, including reference to the config.token variable
- Test 2Render server config and inspect for exposed daemon secret
Expected signal: File write event on server.properties under the server volume, plus Wings daemon log entry for config sync of the test server
- Test 3Verify unpatched Wings version is vulnerable
Expected signal: Command execution log/audit entry for the wings version check on the lab host
Unlock playbooks & atomic tests with Pro
Get the full detection package for CVE-2026-52855 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.
df00tech Pro — £29/user/month