CVE-2026-86177 affects Pterodactyl Panel versions before 1.14.1, where the application fails to validate action-specific permissions during scheduled task creation. Subusers with only the schedule.update permission can exploit this flaw to execute arbitrary console commands on game servers. Attackers can create and immediately trigger scheduled tasks to run console commands, control server power states, or create unauthorized backups. The vulnerability stems from insufficient authorization checks in the task creation and execution logic. A fix was released in Pterodactyl Panel version 1.14.1 via a commit to the main repository. The affected code is located in StoreTaskRequest.php and RunTaskJob.php. This represents a privilege escalation vulnerability that could lead to unauthorized server control. Users are advised to upgrade to v1.14.1 immediately.